Title:Arbitrary File Download Via ConfigSecurityPolicy.EXE Status:test Description:Detects the execution of "ConfigSecurityPolicy.EXE", a binary part of Windows Defender used to manage settings in Windows Defender.
Users can configure different pilot collections for each of the co-management workloads.
It can be abused by attackers in order to upload or download files.
References: -https://lolbas-project.github.io/lolbas/Binaries/ConfigSecurityPolicy/ Author: frack113 Date: 2021-11-26 modified:2022-05-16 Tags: