Skip to content

Shells.Systems

WE POP SHELLS

Category: Research

Abusing Extended Attributes to Bypass Application Control For Business

Posted on 2026-08-052026-08-05 by Ian
Abusing Extended Attributes to Bypass Application Control For Business

Estimated Reading Time: 7 minutesThis post shows a practical bypass of Application Control for Business (formerly Windows Defender Application Control (WDAC)) by abusing NTFS Kernel Extended Attributes (Kernel EAs)

CategoriesPurple Team, Red Team, Research
Proudly powered by WordPress