[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_daq7ajMOiFIuNOYU4j9dUCSqQULIrKP50fQ8tIJSco":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},939,"Why is digital signature verification important for troubleshooting packs, and how can it be bypassed?","Windows checks the digital signature of a troubleshooting pack before running it; if the signature is invalid or untrusted, the execution is blocked. However, attackers can bypass this by using a custom certificate and installing it into the target’s Trusted Root Certification Authorities, making their pack appear legitimate. Alternatively, if they obtain a certificate trusted by default (e.g., from a compromised code signing authority), the pack runs without warnings. This highlights the need for users to verify the publisher identity, as discussed in the [original article](\u002Fnews\u002Fapplication-techniques-of-troubleshooting-platform-in-penetration-testing).","\u003Cp>Windows checks the digital signature of a troubleshooting pack before running it; if the signature is invalid or untrusted, the execution is blocked. However, attackers can bypass this by using a custom certificate and installing it into the target’s Trusted Root Certification Authorities, making their pack appear legitimate. Alternatively, if they obtain a certificate trusted by default (e.g., from a compromised code signing authority), the pack runs without warnings. This highlights the need for users to verify the publisher identity, as discussed in the [original article](\u002Fnews\u002Fapplication-techniques-of-troubleshooting-platform-in-penetration-testing).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fapplication-techniques-of-troubleshooting-platform-in-penetration-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-is-digital-signature-verification-important-for-troubleshooting-packs-and-ho-1777481279549","digital signature, troubleshooting pack, certificate, trusted root, bypass, code signing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},228,"Application Techniques of Troubleshooting Platform in Penetration Testing","application-techniques-of-troubleshooting-platform-in-penetration-testing","Learn how attackers use Windows Troubleshooting Platform for phishing and payload delivery. Explore development techniques, defense strategies, and security insights.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, Matthew Mesa and Axel F from Proofpoint discovered a novel phishing method where attackers use troubleshooting packs as email attachments to deceive users into executing them, thereby covertly running payloads. Their article details the methods and concealment techniques employed by attackers, urging users to remain vigilant.\u003C\u002Fp>\u003Cp>\u003Cstrong>Article link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fthreat-insight\u002Fpost\u002Fwindows-troubleshooting-platform-leveraged-deliver-malware\u003C\u002Fp>\u003Cp>This article will approach from a technical research perspective, explaining how to develop a troubleshooting pack containing a payload, and analyzing defense methods in conjunction with attack strategies, aiming to enhance everyone's understanding of this technology.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Windows Troubleshooting Platform:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>English translation: Windows Troubleshooting Platform, abbreviated as WTP\u003C\u002Fp>\u003Cp>Developers can write troubleshooting packs based on this platform to help users resolve PC issues they encounter\u003C\u002Fp>\u003Cp>WTP structure is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015146387_0_dfa125ab31.jpeg\">\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323706(v=vs.85).aspx\u003C\u002Fp>\u003Cp>The brief process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Check the digital signature of the troubleshooting package; if unavailable, exit directly.\u003C\u002Fli>\u003Cli>Execute detection scripts, resolution scripts, and verification scripts sequentially to attempt to resolve the issue.\u003C\u002Fli>\u003Cli>Generate a result report and a debugging report.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Troubleshooting package:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Consists of five components:\u003C\u002Fp>\u003Cul>\u003Cli>Troubleshooting manifest\u003C\u002Fli>\u003Cli>Detection scripts\u003C\u002Fli>\u003Cli>Resolution scripts\u003C\u002Fli>\u003Cli>Verification scripts\u003C\u002Fli>\u003Cli>Localized resources\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Details are shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015147971_1_ed0b38570f.jpeg\">\u003C\u002Fp>\u003Cp>Cited from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323706(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x02 Developing Troubleshooting Packages\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official Development Tool:\u003C\u002Fp>\u003Cp>TSPDesigner\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This tool is included in the Windows 7 SDK\u003C\u002Fp>\u003Cp>Actual testing shows only v7.0 and v7.1 include this tool\u003C\u002Fp>\u003Cp>Windows 7 SDK version 7.0 requires .NET Framework 3.5 SP1, download link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=3138\u003C\u002Fp>\u003Cp>Windows 7 SDK version 7.1 requires .NET Framework 4, download link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=8279\u003C\u002Fp>\u003Cp>TSPDesigner is located in the default directory C:\\Program Files\\Microsoft SDKs\\Windows\\v7.1\\Bin\\TSPDesigner, containing the following:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015149234_2_d8a0adbc45.png\">\u003C\u002Fp>\u003Cp>Detailed development reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323712(v=vs.85).aspx\u003C\u002Fp>\u003Cp>The following example demonstrates how to generate a troubleshooting pack using TSPDesigner.\u003C\u002Fp>\u003Ch3>1. Set properties, which is the first page of the troubleshooting pack.\u003C\u002Fh3>\u003Cp>Project Name: testwtp\u003C\u002Fp>\u003Cp>Project Description: troubleshooting pack test\u003C\u002Fp>\u003Cp>Privacy URL: https:\u002F\u002Fan-open-source-project\u002F\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015150258_3_7e9750ad1f.png\">\u003C\u002Fp>\u003Ch3>2. Add a root cause. Click Add New Root Cause and set the fault information.\u003C\u002Fh3>\u003Cp>Root Cause ID: ServiceIsStopped\u003C\u002Fp>\u003Cp>Root Cause Name: The service is stopped.\u003C\u002Fp>\u003Cp>Root Cause Description: The service is stopped. You need to enable it.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015152419_4_950acf790b.png\">\u003C\u002Fp>\u003Ch3>3. Set the Troubleshooter.\u003C\u002Fh3>\u003Cp>As shown in the figure, specify that elevated permissions are required and disable interaction.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015154735_5_4432e5ee10.png\">\u003C\u002Fp>\u003Ch3>4. Set Resolver\u003C\u002Fh3>\u003Cp>Resolver Name: StartTheService\u003C\u002Fp>\u003Cp>Resolver Description: Start the service.\u003C\u002Fp>\u003Cp>Prompt the User: No\u003C\u002Fp>\u003Cp>Elevation: Yes\u003C\u002Fp>\u003Cp>Interactions: No\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015156734_6_1625fa684e.png\">\u003C\u002Fp>\u003Cp>Specify that elevation is required, disable user warnings, disable interactions\u003C\u002Fp>\u003Ch3>5. Set Verifier\u003C\u002Fh3>\u003Cp>Select No, no need to confirm the issue is resolved\u003C\u002Fp>\u003Ch3>6. Set Scripts\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015158487_7_378b84a7a1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since elevated privileges were specified in steps 3 and 4, the Troubleshooter Script and Resolver Script here already have administrator permissions\u003C\u002Fp>\u003Cp>Payload can be added here\u003C\u002Fp>\u003Ch3>7. Set digital signature\u003C\u002Fh3>\u003Cp>Select Project-Options, find Code Signing\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015159631_8_ec313dd023.png\">\u003C\u002Fp>\u003Cp>You can choose to use Test Certificate or specify a certificate\u003C\u002Fp>\u003Cp>By default, select Use Generated Test Certificate for testing\u003C\u002Fp>\u003Ch3>8. Generate\u003C\u002Fh3>\u003Cp>Select Build-Build Pack\u003C\u002Fp>\u003Cp>The following files are generated:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015160655_9_cddddf1c93.png\">\u003C\u002Fp>\u003Cp>1.\u003C\u002Fp>\u003Cp>TS_ServiceIsStopped.ps1 corresponds to Troubleshooter Script\u003C\u002Fp>\u003Cp>RS_ServiceIsStopped.ps1 corresponds to Resolver Script\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Examining these two ps scripts reveals the payloads they contain\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>testwtp.diagpkg is the manifest file, containing parameters for the troubleshooting pack, in XML format. For specific syntax, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323781(v=vs.85).aspx\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>DiagPackage.cat stores the digital signature of this troubleshooting pack\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The digital signature in the DiagPackage.cat file can be viewed by double-clicking\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015160921_10_b895a5f5af.png\">\u003C\u002Fp>\u003Cp>4.\u003C\u002Fp>\u003Cp>testwtp.diagcab under the cab directory is the packaged troubleshooting pack, containing information from the above files\u003C\u002Fp>\u003Cp>As shown, during runtime the payload executes and launches a cmd.exe with administrator privileges\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015161616_11_1596f1596c.png\">\u003C\u002Fp>\u003Ch2>0x03 Testing Run Troubleshooting Package\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Place the generated .diagcab file on another test system\u003C\u002Fp>\u003Cp>Error reported, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015162148_12_7ee113383b.png\">\u003C\u002Fp>\u003Cp>This occurs because the default Test Certificate used is not recognized on the new system. Locate the certificate file TestWindowsTroubleShooting.cer in the same directory as TSPDesigner and install it into the Trusted Root Certification Authorities, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015162334_13_34680711f8.png\">\u003C\u002Fp>\u003Cp>Digital signature successfully recognized, as shown below\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The publisher name displayed here corresponds to the issuer used by the signing certificate, which is TestCertforWindowsTroubleShooting\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015162648_14_103c2fb803.png\">\u003C\u002Fp>\u003Cp>Of course, if a certificate that is trusted by default is used, then this troubleshooting package is trusted by default and can be run directly\u003C\u002Fp>\u003Cp>Click the privacy statement to open the Privacy URL set in Step 1: https:\u002F\u002Fan-open-source-project\u002F\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015162917_15_8864d01506.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the test troubleshooting pack has been successfully implemented\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using a troubleshooting pack offers the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>More covert, as .diagcab files are uncommon\u003C\u002Fli>\u003Cli>More deceptive, as users often let their guard down with troubleshooting functions\u003C\u002Fli>\u003Cli>Direct administrator privileges can be obtained\u003C\u002Fli>\u003Cli>Embedded phishing pages with customizable privacy policy links\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Defense recommendations:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Microsoft recognized this issue early on and added digital signature verification for troubleshooting packs. Therefore, when encountering a troubleshooting pack (e.g., when an operation triggers fault repair), the first step is to verify the publisher's identity.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In Microsoft-provided troubleshooting packs, the publisher name defaults to Microsoft Corporation\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, Matthew Mesa and Axel F from Proofpoint discovered a novel phishing method where attackers use troubleshooting packs as email attachments to deceive users into executing them, thereby covertly running payloads. Their article details the methods and concealment techniques employed by attackers, urging users to remain vigilant.\u003C\u002Fp>\u003Cp>\u003Cstrong>Article link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fthreat-insight\u002Fpost\u002Fwindows-troubleshooting-platform-leveraged-deliver-malware\u003C\u002Fp>\u003Cp>This article will approach from a technical research perspective, explaining how to develop a troubleshooting pack containing a payload, and analyzing defense methods in conjunction with attack strategies, aiming to enhance everyone's understanding of this technology.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Windows Troubleshooting Platform:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>English translation: Windows Troubleshooting Platform, abbreviated as WTP\u003C\u002Fp>\u003Cp>Developers can write troubleshooting packs based on this platform to help users resolve PC issues they encounter\u003C\u002Fp>\u003Cp>WTP structure is shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015146387_0_dfa125ab31-1.jpeg\">\u003C\u002Fp>\u003Cp>Image referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323706(v=vs.85).aspx\u003C\u002Fp>\u003Cp>The brief process is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Check the digital signature of the troubleshooting package; if unavailable, exit directly.\u003C\u002Fli>\u003Cli>Execute detection scripts, resolution scripts, and verification scripts sequentially to attempt to resolve the issue.\u003C\u002Fli>\u003Cli>Generate a result report and a debugging report.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Troubleshooting package:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Consists of five components:\u003C\u002Fp>\u003Cul>\u003Cli>Troubleshooting manifest\u003C\u002Fli>\u003Cli>Detection scripts\u003C\u002Fli>\u003Cli>Resolution scripts\u003C\u002Fli>\u003Cli>Verification scripts\u003C\u002Fli>\u003Cli>Localized resources\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Details are shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015147971_1_ed0b38570f-1.jpeg\">\u003C\u002Fp>\u003Cp>Cited from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323706(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x02 Developing Troubleshooting Packages\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Official Development Tool:\u003C\u002Fp>\u003Cp>TSPDesigner\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This tool is included in the Windows 7 SDK\u003C\u002Fp>\u003Cp>Actual testing shows only v7.0 and v7.1 include this tool\u003C\u002Fp>\u003Cp>Windows 7 SDK version 7.0 requires .NET Framework 3.5 SP1, download link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=3138\u003C\u002Fp>\u003Cp>Windows 7 SDK version 7.1 requires .NET Framework 4, download link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fdownload\u002Fdetails.aspx?id=8279\u003C\u002Fp>\u003Cp>TSPDesigner is located in the default directory C:\\Program Files\\Microsoft SDKs\\Windows\\v7.1\\Bin\\TSPDesigner, containing the following:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015149234_2_d8a0adbc45-1.png\">\u003C\u002Fp>\u003Cp>Detailed development reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323712(v=vs.85).aspx\u003C\u002Fp>\u003Cp>The following example demonstrates how to generate a troubleshooting pack using TSPDesigner.\u003C\u002Fp>\u003Ch3>1. Set properties, which is the first page of the troubleshooting pack.\u003C\u002Fh3>\u003Cp>Project Name: testwtp\u003C\u002Fp>\u003Cp>Project Description: troubleshooting pack test\u003C\u002Fp>\u003Cp>Privacy URL: https:\u002F\u002Fan-open-source-project\u002F\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015150258_3_7e9750ad1f-1.png\">\u003C\u002Fp>\u003Ch3>2. Add a root cause. Click Add New Root Cause and set the fault information.\u003C\u002Fh3>\u003Cp>Root Cause ID: ServiceIsStopped\u003C\u002Fp>\u003Cp>Root Cause Name: The service is stopped.\u003C\u002Fp>\u003Cp>Root Cause Description: The service is stopped. You need to enable it.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015152419_4_950acf790b-1.png\">\u003C\u002Fp>\u003Ch3>3. Set the Troubleshooter.\u003C\u002Fh3>\u003Cp>As shown in the figure, specify that elevated permissions are required and disable interaction.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015154735_5_4432e5ee10-1.png\">\u003C\u002Fp>\u003Ch3>4. Set Resolver\u003C\u002Fh3>\u003Cp>Resolver Name: StartTheService\u003C\u002Fp>\u003Cp>Resolver Description: Start the service.\u003C\u002Fp>\u003Cp>Prompt the User: No\u003C\u002Fp>\u003Cp>Elevation: Yes\u003C\u002Fp>\u003Cp>Interactions: No\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015156734_6_1625fa684e-1.png\">\u003C\u002Fp>\u003Cp>Specify that elevation is required, disable user warnings, disable interactions\u003C\u002Fp>\u003Ch3>5. Set Verifier\u003C\u002Fh3>\u003Cp>Select No, no need to confirm the issue is resolved\u003C\u002Fp>\u003Ch3>6. Set Scripts\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015158487_7_378b84a7a1-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since elevated privileges were specified in steps 3 and 4, the Troubleshooter Script and Resolver Script here already have administrator permissions\u003C\u002Fp>\u003Cp>Payload can be added here\u003C\u002Fp>\u003Ch3>7. Set digital signature\u003C\u002Fh3>\u003Cp>Select Project-Options, find Code Signing\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015159631_8_ec313dd023-1.png\">\u003C\u002Fp>\u003Cp>You can choose to use Test Certificate or specify a certificate\u003C\u002Fp>\u003Cp>By default, select Use Generated Test Certificate for testing\u003C\u002Fp>\u003Ch3>8. Generate\u003C\u002Fh3>\u003Cp>Select Build-Build Pack\u003C\u002Fp>\u003Cp>The following files are generated:\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015160655_9_cddddf1c93-1.png\">\u003C\u002Fp>\u003Cp>1.\u003C\u002Fp>\u003Cp>TS_ServiceIsStopped.ps1 corresponds to Troubleshooter Script\u003C\u002Fp>\u003Cp>RS_ServiceIsStopped.ps1 corresponds to Resolver Script\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Examining these two ps scripts reveals the payloads they contain\u003C\u002Fp>\u003Cp>2.\u003C\u002Fp>\u003Cp>testwtp.diagpkg is the manifest file, containing parameters for the troubleshooting pack, in XML format. For specific syntax, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fdd323781(v=vs.85).aspx\u003C\u002Fp>\u003Cp>3.\u003C\u002Fp>\u003Cp>DiagPackage.cat stores the digital signature of this troubleshooting pack\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The digital signature in the DiagPackage.cat file can be viewed by double-clicking\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015160921_10_b895a5f5af-1.png\">\u003C\u002Fp>\u003Cp>4.\u003C\u002Fp>\u003Cp>testwtp.diagcab under the cab directory is the packaged troubleshooting pack, containing information from the above files\u003C\u002Fp>\u003Cp>As shown, during runtime the payload executes and launches a cmd.exe with administrator privileges\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015161616_11_1596f1596c-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Testing Run Troubleshooting Package\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Place the generated .diagcab file on another test system\u003C\u002Fp>\u003Cp>Error reported, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015162148_12_7ee113383b-1.png\">\u003C\u002Fp>\u003Cp>This occurs because the default Test Certificate used is not recognized on the new system. Locate the certificate file TestWindowsTroubleShooting.cer in the same directory as TSPDesigner and install it into the Trusted Root Certification Authorities, as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015162334_13_34680711f8-1.png\">\u003C\u002Fp>\u003Cp>Digital signature successfully recognized, as shown below\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The publisher name displayed here corresponds to the issuer used by the signing certificate, which is TestCertforWindowsTroubleShooting\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015162648_14_103c2fb803-1.png\">\u003C\u002Fp>\u003Cp>Of course, if a certificate that is trusted by default is used, then this troubleshooting package is trusted by default and can be run directly\u003C\u002Fp>\u003Cp>Click the privacy statement to open the Privacy URL set in Step 1: https:\u002F\u002Fan-open-source-project\u002F\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015162917_15_8864d01506-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the test troubleshooting pack has been successfully implemented\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, using a troubleshooting pack offers the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>More covert, as .diagcab files are uncommon\u003C\u002Fli>\u003Cli>More deceptive, as users often let their guard down with troubleshooting functions\u003C\u002Fli>\u003Cli>Direct administrator privileges can be obtained\u003C\u002Fli>\u003Cli>Embedded phishing pages with customizable privacy policy links\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Defense recommendations:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Microsoft recognized this issue early on and added digital signature verification for troubleshooting packs. Therefore, when encountering a troubleshooting pack (e.g., when an operation triggers fault repair), the first step is to verify the publisher's identity.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In Microsoft-provided troubleshooting packs, the publisher name defaults to Microsoft Corporation\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",612,"Onedaysec",4,"published","2026-02-02T07:25:20.011Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Troubleshooting Platform Penetration Testing & Payload Techniques","Windows Troubleshooting Platform, penetration testing, payload delivery, phishing attacks, TSPDesigner, cybersecurity, malware, troubleshooting pack development",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],940,938,937,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.707Z","2026-07-23T16:02:18.253Z","draft","2026-07-23T16:15:39.453Z"]