Code Integrity Rules
Windows Defender Application Control (WDAC) code integrity rules define the execution policies that govern which code can run on a system. These rules are critical for enforcing security boundaries by restricting unsigned, untrusted, or unauthorized code. By leveraging WDAC policies, administrators can ensure that only trusted binaries, signed by approved publishers, or code from specific paths are allowed to execute. This section explains how to define and manage code integrity rules effectively.
Understanding Code Integrity Rule Types¶
WDAC supports three primary rule types for code integrity:
1. AllSigned: All code must be signed by a trusted certificate. Unsigned or unsigned-by-unknown-publishers code is blocked.
2. RequireSigned: Code must be signed, but unsigned code is allowed (e.g., for legacy applications).
3. Unrestricted: No restrictions (not recommended for production environments).
Rules can also specify allowed publishers using certificate thumbprints or paths. For example, allowing code signed by "Contoso, Inc." or restricting execution to a specific directory.
Creating Code Integrity Rules with PowerShell¶
Use the New-WdacPolicy cmdlet to define rules. Example:
New-WdacPolicy -Policy AllSigned -FilePath "C:\WDAC\CodeIntegrity.xml" -Publisher "Contoso, Inc." -Thumbprint "A1B2C3D4E5F67890"
Example: Restricting Execution to Signed Code¶
New-WdacPolicy -Policy RequireSigned -FilePath "C:\WDAC\RequireSigned.xml" -Publisher "Microsoft Corporation" -PassThru
-PassThru parameter outputs potential conflicts (e.g., unsigned binaries) without applying the policy.
Managing Rule Conflicts and Validation¶
Before deploying a policy, validate it using Test-WdacPolicy:
Troubleshooting Common Issues¶
- Invalid Publisher Certificates: Ensure the thumbprint matches the certificate used to sign the code.
- Missing Dependencies: Verify that all required binaries are signed and included in the policy.
- Policy Conflicts: Use
Get-WdacPolicyto review existing rules and resolve overlaps.
Best Practices for Code Integrity Rules¶
- Limit Publisher Trust: Avoid granting trust to unknown or unverified publishers.
- Use Specific Paths: Restrict execution to trusted directories (e.g.,
C:\Program Files\), not just signed code. - Test in Isolation: Validate policies in a non-production environment before deployment.
- Regularly Update Certificates: Rotate or replace expired certificates to maintain compliance.
Key takeaways¶
- Code integrity rules enforce execution policies to block unsigned or untrusted code.
- Use
New-WdacPolicyto define rules, specifying publishers or paths as needed. - Validate policies with
Test-WdacPolicyto identify conflicts before deployment. - Prioritize specific publisher trust and path restrictions over broad policies.
- Always test policies in a controlled environment to avoid unintended disruptions.