Post #1260250
2026-04-09 20:31 UTC
PowerShell Desired State Configuration supports a feature I'm very proud of: you can tell nodes to only allow configuration documents signed by a specified publisher. So if the host these things are pulling their configuration documents from gets popped, you have no risk of company-wide remote code execution unless they also got your signing key.
This saves you from attacks like this that leverage trusted internal supply chains like Group Policy: https://blog.quest.com/how-attackers-abuse-group-policy-and-how-to-thwart-them/
Replies (0)
No replies.