Potential Signing Bypass Via Windows Developer Features

Rule Info

Name
Potential Signing Bypass Via Windows Developer Features
Description
Detects when a user enable developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.
Reference
Internal Research
Modified
None
Date
2023-01-11 00:00:00
Author
Nasreddine Bencherchali (Nextron Systems)
Tags
attack.defense_evasion DEMO
Id
a383dec4-deec-4e6e-913b-ed9249670848
Type
Community Rule

Rule History

Author
Commit
Title
Date
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
Nasreddine Bencherchali
feat: add new reg variant of dev mode
2023-01-12
Nasreddine Bencherchali
feat: new rules related to appx packages
2023-01-11