WINDOWS DEFENDER EXPLOIT PROTECTION POWERSHELL SCRIPTS TO ENABLE OR DISABLE PROCESS MIGITATION COMPONENTS

  • Thread starter Thread starter RAJU.MSC
  • Start date Start date
R

RAJU.MSC

I am sharing some PowerShell scripts to enable migration process components at system level


Just open WINDOWS POWERSHELL run as administrator and enter the following commands to enable

Set-ProcessMitigation System -enable AllowStoreSignedBinaries
Set-ProcessMitigation System -enable AllowThreadsToOptOut
Set-ProcessMitigation System -enable BlockDynamicCode
Set-ProcessMitigation System -enable BlockLowLabelImageLoads
Set-ProcessMitigation system -enable BlockRemoteImageLoads
Set-ProcessMitigation system -enable BottomUp
Set-ProcessMitigation system -enable CFG
Set-ProcessMitigation system -enable DEP
Set-ProcessMitigation System -enable DisableExtensionPoints
Set-ProcessMitigation System -enable DisableNonSystemFonts
Set-ProcessMitigation System -enable DisableWin32kSystemCalls
Set-ProcessMitigation System -enable DisallowChildProcessCreation
Set-ProcessMitigation System -enable EmulateAtlThunks
Set-ProcessMitigation system -enable EnableExportAddressFilter
Set-ProcessMitigation system -enable EnableExportAddressFilterPlus
Set-ProcessMitigation system -enable EnableImportAddressFilter
Set-ProcessMitigation system -enable EnableRopCallerCheck
Set-ProcessMitigation system -enable EnableRopSimExec
Set-ProcessMitigation system -enable EnableRopStackPivot
Set-ProcessMitigation System -enable EnforceModuleDependencySigning
Set-ProcessMitigation system -enable ForceRelocateImages
Set-ProcessMitigation System -enable HighEntropy
Set-ProcessMitigation System -enable MicrosoftSignedOnly
Set-ProcessMitigation System -enable PreferSystem32
Set-ProcessMitigation System -enable RequireInfo
Set-ProcessMitigation system -enable SEHOP
Set-ProcessMitigation system -enable StrictHandle
Set-ProcessMitigation system -enable SuppressExports
Set-ProcessMitigation system -enable TerminateOnError



to Disable migration process components at system level


Just open WINDOWS POWERSHELL run as administrator and enter the following commands to Disable


Set-ProcessMitigation System -disable AllowStoreSignedBinaries
Set-ProcessMitigation System -disable AllowThreadsToOptOut
Set-ProcessMitigation System -disable BlockDynamicCode
Set-ProcessMitigation System -disable BlockLowLabelImageLoads
Set-ProcessMitigation system -disable BlockRemoteImageLoads
Set-ProcessMitigation system -disable BottomUp
Set-ProcessMitigation system -disable CFG
Set-ProcessMitigation system -disable DEP
Set-ProcessMitigation System -disable DisableExtensionPoints
Set-ProcessMitigation System -disable DisableNonSystemFonts
Set-ProcessMitigation System -disable DisableWin32kSystemCalls
Set-ProcessMitigation System -disable DisallowChildProcessCreation
Set-ProcessMitigation System -disable EmulateAtlThunks
Set-ProcessMitigation system -disable EnableExportAddressFilter
Set-ProcessMitigation system -disable EnableExportAddressFilterPlus
Set-ProcessMitigation system -disable EnableImportAddressFilter
Set-ProcessMitigation system -disable EnableRopCallerCheck
Set-ProcessMitigation system -disable EnableRopSimExec
Set-ProcessMitigation system -disable EnableRopStackPivot
Set-ProcessMitigation System -disable EnforceModuleDependencySigning
Set-ProcessMitigation system -disable ForceRelocateImages
Set-ProcessMitigation System -disable HighEntropy
Set-ProcessMitigation System -disable MicrosoftSignedOnly
Set-ProcessMitigation System -disable PreferSystem32
Set-ProcessMitigation System -disable RequireInfo
Set-ProcessMitigation system -disable SEHOP
Set-ProcessMitigation system -disable StrictHandle
Set-ProcessMitigation system -disable SuppressExports
Set-ProcessMitigation system -disable TerminateOnError



above commands are used to Disable protection at system level


for more information visit below micosoft website :

Enable or disable specific mitigations used by Exploit protection


I am requesting moderators and engineers to review my article is it ok for windows 10 , PLEASE COMMENTS HERE

I have enabled above process migitation components in my windows 10 laptop







Moved from: Windows 10 / Security & privacy

Continue reading...
 
Back
Top