Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WDAC Wizard crashes when creating a file path allow rule in a supplemental policy #427

Open
UB01609 opened this issue Dec 12, 2024 · 3 comments

Comments

@UB01609
Copy link

UB01609 commented Dec 12, 2024

WDAC Wizard crashes when creating a file path allow rule in a supplemental policy. Also enabling UMCI at the same time. Does not crash when creating a file path allow rule in a base policy, only in supplemental policy. Trying to create file path allow rule for "C:\Users\UB01609\AppData\Local\HP\ALM-Client" directory.

How to recreate:
Settings App (version 2.5.01):
{248E6458-6279-4C43-81C4-23FCE449FA71}
Create a file path allow rule in a supplemental policy:
image
Make sure UMCI is enabled (not sure if this is 100% required to recreate.
image
Try and create supplemental policy. Wizard should crash:
image

@UB01609
Copy link
Author

UB01609 commented Dec 12, 2024

I realize the pictures make it look like I was trying to implement the file path allow rule in kernel mode; this is not the case. I turned kernel mode off prior to creating the rule.

@UB01609
Copy link
Author

UB01609 commented Dec 12, 2024

Adding log files from "C:\Users\UB01609\AppData\Local\Temp" (.log file is empty; Unable to upload .db-wal file because of file type restrictions.)
mat-debug-3352.log

@UB01609
Copy link
Author

UB01609 commented Dec 18, 2024

Fixed by changing ProductSigners field under ID_SIGNINGSCENARIO_WINDOWS from:
image
to
image
I believe this was caused by me manually removing hash allows incorrectly. I tested this with the WDAC Wizard and found that it works as expected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant