Allowlist Auditor v4.1

Five new tests to help you harden your allowlist, plus rebuilt WDAC policy inspection.

The Allowlist Auditor is a free utility from Airlock Digital that tests application allowlists for misconfigurations and weaknesses. Version 4.1 goes beyond configuration gaps and tests techniques that could be used to circumvent an allowlist. These include the Microsoft Recommended User Mode Blocklist, ClickFix, ClickOnce, PowerShell downgrade and .NET assembly reflection. This auditor works with any allowlisting product and is separate from the Airlock Digital allowlisting offering.

 

Why test an allowlist?

An allowlist is only as strong as two things: its configuration and the capability of the allowlisting solution to mitigate bypasses. The Allowlist Auditor from Airlock Digital validates both of these items by testing the efficacy of an allowlisting implementation.

 

What is new in the Allowlist Auditor?

The allowlist auditor contains tests for the following attack techniques.

 

User Mode Blocklist

Microsoft publishes a list of its own signed binaries that can be abused to run code, such as msbuild.exe, bash.exe and wsl.exe. Because these binaries could possibly be used to bypass application control and are signed by Microsoft, in many allowlist configurations they are often permitted. The auditor finds these files on the machine and tries to load or execute them. Airlock Digital comes with the predefined blocklist, ‘Microsoft recommended block rules (main)’, for these binaries. It is based on Microsoft's official list and can be applied immediately as a mitigation. This list can also be adjusted so that internal tools that rely on them can still use these binaries, while they cannot be used to run untrusted code.

ClickFix

ClickFix is a social engineering technique on Windows machines where a web page tricks a user into running a command using the start menu Run box. The command typically uses PowerShell, CMD or curl to download and run the attacker's code. The auditor tests 12 variants of this, including hidden and encoded commands, either simulated or typed into the real Run dialog. Airlock Digital can check whether PowerShell or CMD was started from Windows Run and, if so, what the command contains. The “ClickFix Hardening” blocklist is available in Airlock Digital to block these ClickFix attempts. The blocklist serves as a baseline and can be adjusted to better fit each specific environment.

ClickOnce

ClickOnce is an attack technique that turns Microsoft's ClickOnce installer into a way to install and run an attacker's application. Because ClickOnce installs into the user's own profile without admin rights and is started by a signed Microsoft component, the attacker's application can pass for a normal software installation. The auditor launches a test ClickOnce application and checks whether it can install and run. Airlock Digital stops these unwanted ClickOnce installations with the ready-made blocklist ‘Dfsvc (ClickOnce Engine).’

ClickOnce

PowerShell downgrade is an attack technique where an attacker launches an older version of PowerShell v2 that predates AMSI, Constrained Language Mode and script block logging. AMSI lets antivirus inspect a script before it runs, Constrained Language Mode limits what a script can do, and script block logging records what it did. The auditor tests whether a PowerShell version 2 session can be started. Airlock Digital can specifically prevent version 2 from starting with the ‘PowerShell v2 Engine’ blocklist, which blocks older version of PowerShell to run, while current versions of PowerShell keep working as normal.

.NET assembly reflection

.NET assembly reflection is an attack technique where an attacker gets a program that is already allowed to run, to load their code for them. Because the code is loaded directly into memory and never saved as a file, many allowlisting products on the market lack visibility over this technique. The auditor tests nine reflection methods to see whether trusted programs can load code this way. Airlock Digital offers Assembly Reflection Prevention, a policy setting enabled by default that stops trusted programs from loading code from memory.

 

What has been improved in this release of the Allowlist Auditor?

WDAC and Device Guard inspection

WDAC (Windows Defender Application Control) is an application control feature built into Windows. Newer versions of Windows can run several WDAC policies side by side, including supplemental policies that add rules on top of a base policy. The auditor now reads every active policy, groups supplemental policies under their base policy and shows in more detail what each policy allows and blocks.

Guided Mode and Advanced Mode

The new auditor has two test modes:

  • Guided Mode: Gives you 2 predefined testing options: either a Shallow Test, which checks only a few folder locations and runs the fastest, least invasive versions of the attacks, or a Thorough Test, which checks more folders and runs more realistic versions of the tests at the expense of taking longer.

  • Advanced Mode: Lets you first inspect the WDAC or AppLocker policy on the machine. You can then choose which tests to run, which version of each test runs and exactly where to run them.

Whatever allowlisting solution you use, we hope this utility helps you validate and improve your implementation and drive greater security within your environment. You can download the Allowlist Auditor here. If you have any feedback on this utility and would like to request additional features, please reach out.

 

Allowlist Auditor FAQ

It runs on Windows 10 and Windows 11 on x86, x64 and ARM64 machines. Policy inspection is available for AppLocker and for both the original single policy WDAC format and the current multiple policy format.

The auditor requires Windows with .NET Framework 4.8. If your allowlist blocks it, allow the auditor executable by its hash (4ad041fb99e7ec79f6e07f0095ae6e4da03a7bc74d47105596ec4c4b4b163a92) or publisher (Airlock Digital Pty Ltd). Run it as a standard user. For the most reliable results, turn off sleep and the screen saver and do not lock the machine while the tests run.

The Allowlist Auditor does not block anything. It is a free testing tool that you run on a single machine to validate your current allowlisting setup. Airlock Digital is the product that enforces allowlisting across your whole environment, with central management of policies, approvals and audit logs.

Every result marked "Block failed" shows where your setup can be strengthened, and the report tells you what to change. You can use this to adjust your allowlisting solution and close each gap. Airlock Digital can protect against these techniques. Contact us to see how Airlock Digital can help make your environment more secure.

It depends on the machine and is heavily influenced by how many folders it has. The auditor counts them in the background and shows a rough estimate before you start. Shallow Test is the fastest and usually finishes within a few minutes. Thorough Test takes around an hour, or longer on older devices or devices with many files. In Custom Test or Advanced Mode with maximum coverage, a run can take 12 hours or more. Most of that time is spent validating the Microsoft recommended user mode blocklist test as well as writing, running and deleting test files in every folder on the machine.

Yes. All test files are harmless and are deleted straight after each test. The ClickFix commands only connect to a test server on the local machine, and nothing is downloaded from the internet.

EDR (endpoint detection and response) tools watch for suspicious behavior on a machine. In testing Airlock Digital has not observed general tests being blocked by EDR, however some tests may cause an AV/EDR detection to be raised due to the nature of this utility, as it simulates attack techniques.