Skip to content

Instantly share code, notes, and snippets.

@mgraeber-rc
Created September 14, 2023 18:58
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save mgraeber-rc/5737a6a6a8967cd25b8bcad2c2df458b to your computer and use it in GitHub Desktop.
Save mgraeber-rc/5737a6a6a8967cd25b8bcad2c2df458b to your computer and use it in GitHub Desktop.
Recovered WDAC Inbox Policy: VerifiedAndReputableDesktopFlightSupplemental
<?xml version="1.0"?>
<SiPolicy xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" PolicyType="Supplemental Policy" xmlns="urn:schemas-microsoft-com:sipolicy">
<VersionEx>0.0.0.0</VersionEx>
<PlatformID>{2E07F7E4-194C-4D20-B7C9-6F44A6C5A234}</PlatformID>
<PolicyID>{1678656C-05EF-481F-BC5B-EBD8C991502D}</PolicyID>
<BasePolicyID>{0283AC0F-FFF1-49AE-ADA1-8A933130CAD6}</BasePolicyID>
<Rules>
<Rule>
<Option>Enabled:UMCI</Option>
</Rule>
</Rules>
<EKUs>
<EKU ID="ID_EKU_E_0001" Value="010A2B0601040182370A0306" FriendlyName="Windows System Component Verification" />
<EKU ID="ID_EKU_E_0002" Value="010A2B0601040182373D0401" FriendlyName="Early Launch Antimalware Driver" />
<EKU ID="ID_EKU_E_0003" Value="010A2B0601040182373D0501" FriendlyName="HAL Extension" />
<EKU ID="ID_EKU_E_0004" Value="010A2B0601040182370A0305" FriendlyName="Windows Hardware Driver Verification" />
</EKUs>
<Signers>
<Signer Name="Signer 1" ID="ID_SIGNER_S_0001">
<CertRoot Type="Wellknown" Value="0E" />
</Signer>
<Signer Name="Signer 2" ID="ID_SIGNER_S_0002">
<CertRoot Type="Wellknown" Value="0E" />
<CertEKU ID="ID_EKU_E_0001" />
</Signer>
<Signer Name="Signer 3" ID="ID_SIGNER_S_0003">
<CertRoot Type="Wellknown" Value="0E" />
<CertEKU ID="ID_EKU_E_0002" />
</Signer>
<Signer Name="Signer 4" ID="ID_SIGNER_S_0004">
<CertRoot Type="Wellknown" Value="0E" />
<CertEKU ID="ID_EKU_E_0003" />
</Signer>
<Signer Name="Signer 5" ID="ID_SIGNER_S_0005">
<CertRoot Type="Wellknown" Value="0E" />
<CertEKU ID="ID_EKU_E_0004" />
</Signer>
<Signer Name="Signer 6" ID="ID_SIGNER_S_0006">
<CertRoot Type="Wellknown" Value="06" />
<CertEKU ID="ID_EKU_E_0001" />
</Signer>
<Signer Name="Signer 7" ID="ID_SIGNER_S_0007">
<CertRoot Type="Wellknown" Value="0A" />
</Signer>
</Signers>
<SigningScenarios>
<SigningScenario ID="ID_SIGNINGSCENARIO_DRIVERS_1" Value="131">
<ProductSigners>
<AllowedSigners>
<AllowedSigner SignerId="ID_SIGNER_S_0002" />
<AllowedSigner SignerId="ID_SIGNER_S_0003" />
<AllowedSigner SignerId="ID_SIGNER_S_0004" />
<AllowedSigner SignerId="ID_SIGNER_S_0005" />
</AllowedSigners>
</ProductSigners>
<TestSigners />
<TestSigningSigners />
</SigningScenario>
<SigningScenario ID="ID_SIGNINGSCENARIO_WINDOWS" Value="12">
<ProductSigners>
<AllowedSigners>
<AllowedSigner SignerId="ID_SIGNER_S_0001" />
</AllowedSigners>
</ProductSigners>
<TestSigners />
<TestSigningSigners />
</SigningScenario>
</SigningScenarios>
<UpdatePolicySigners>
<UpdatePolicySigner SignerId="ID_SIGNER_S_0006" />
<UpdatePolicySigner SignerId="ID_SIGNER_S_0002" />
<UpdatePolicySigner SignerId="ID_SIGNER_S_0007" />
</UpdatePolicySigners>
<CiSigners>
<CiSigner SignerId="ID_SIGNER_S_0001" />
</CiSigners>
<Settings>
<Setting Provider="PolicyInfo" Key="Information" ValueName="Id">
<Value>
<String>22512.1000.211129</String>
</Value>
</Setting>
<Setting Provider="PolicyInfo" Key="Information" ValueName="Name">
<Value>
<String>VerifiedAndReputableDesktopFlightSupplemental</String>
</Value>
</Setting>
</Settings>
</SiPolicy>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment