Windows 10 Enterprise with Secure Boot enabled with Credential Guard enabled stops Petya in its tracks. All built in features.
-
-
Few actually deploy the built in protections. Also Windows Firewall stops inbound SMB by default but everybody disables it.
- Pokaż odpowiedzi
Nowa rozmowa -
-
-
Stops credential theft - means you won't infect other machines, no? But would it prevent infection of a Win10 PC from a Win8?
-
Probably not. You'd have to bring your estate up to scratch. (Although to be honest if you just firewalled SMB internally you'd be fine).
- Pokaż odpowiedzi
Nowa rozmowa -
-
-
Specifically with regard to Secure Boot: wouldn't Petya still overwrite the GPT though?
-
Nope, don't believe so
- Pokaż odpowiedzi
Nowa rozmowa -
-
-
My working theory was that Secure Boot would prevent the system from booting after tampering, stopping it from reaching fake CHKDSK stage
-
Secure Boot ignores MBR as it books from UEFI, so you don't go into tampered boot
Koniec rozmowy
Nowa rozmowa -
Wydaje się, że ładowanie zajmuje dużo czasu.
Twitter jest przeciążony lub wystąpił chwilowy problem. Spróbuj ponownie lub sprawdź status Twittera, aby uzyskać więcej informacji.
my tweets are severely limited by my lack of understanding of what I am doing.
