# Module manifest for module 'WDACConfig' # Generated by: HotCakeX # Generated on: 4/2/2023 @{ # Script module or binary module file associated with this manifest. # RootModule = "" # Version number of this module. ModuleVersion = '0.2.0' # Supported PSEditions CompatiblePSEditions = @("Core") # ID used to uniquely identify this module GUID = '79920947-efb5-48c1-a567-5b02ebe74793' # Author of this module Author = 'HotCakeX' # Company or vendor of this module CompanyName = 'SpyNetGirl' # Copyright statement for this module Copyright = '(c) 2023' # Description of the functionality provided by this module Description = @" This is an advanced PowerShell module for WDAC (Windows Defender Application Control) and automates a lot of tasks. 🟢 Please see the GitHub page for Full details and everything about the module: https://github.com/HotCakeX/Harden-Windows-Security/wiki/WDACConfig 🛡️ Here is the list of module's cmdlets ✔️ New-WDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/New-WDACConfig ✔️ New-SupplementalWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/New-SupplementalWDACConfig ✔️ Remove-WDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Remove-WDACConfig ✔️ Edit-WDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Edit-WDACConfig ✔️ Edit-SignedWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Edit-SignedWDACConfig ✔️ Deploy-SignedWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Deploy-SignedWDACConfig ✔️ Confirm-WDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Confirm-WDACConfig ✔️ New-DenyWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/New-DenyWDACConfig ✔️ Set-CommonWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Set-CommonWDACConfig ✔️ New-KernelModeWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/New%E2%80%90KernelModeWDACConfig ✔️ Get-CommonWDACConfig: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Get-CommonWDACConfig ✔️ Invoke-WDACSimulation: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Invoke-WDACSimulation To get help and syntax on PowerShell console, type: "Get-Command -Module WDACConfig" "Get-Help New-WDACConfig" "Get-Help New-SupplementalWDACConfig" "Get-Help Remove-WDACConfig" "Get-Help Edit-WDACConfig" "Get-Help Edit-SignedWDACConfig" "Get-Help Deploy-SignedWDACConfig" "Get-Help Confirm-WDACConfig" "Get-Help New-DenyWDACConfig" "Get-Help Set-CommonWDACConfig" "Get-help New-KernelModeWDACConfig" "Get-help Get-CommonWDACConfig" "Get-help Invoke-WDACSimulation" "@ # Minimum version of the PowerShell engine required by this module PowerShellVersion = '7.3.4' # Name of the PowerShell host required by this module # PowerShellHostName = '' # Minimum version of the PowerShell host required by this module # PowerShellHostVersion = '' # Minimum version of Microsoft .NET Framework required by this module. This prerequisite is valid for the PowerShell Desktop edition only. # DotNetFrameworkVersion = '' # Minimum version of the common language runtime (CLR) required by this module. This prerequisite is valid for the PowerShell Desktop edition only. # ClrVersion = '' # Processor architecture (None, X86, Amd64) required by this module # ProcessorArchitecture = '' # Modules that must be imported into the global environment prior to importing this module # RequiredModules = @() # Assemblies that must be loaded prior to importing this module # RequiredAssemblies = @() # Script files (.ps1) that are run in the caller's environment prior to importing this module. # ScriptsToProcess = @() # Type files (.ps1xml) to be loaded when importing this module # TypesToProcess = @() # Format files (.ps1xml) to be loaded when importing this module # FormatsToProcess = @() # Modules to import as nested modules of the module specified in RootModule/ModuleToProcess NestedModules = @("New-WDACConfig.psm1", "Remove-WDACConfig.psm1", "Deploy-SignedWDACConfig.psm1", "Confirm-WDACConfig.psm1", "Edit-WDACConfig.psm1", "Edit-SignedWDACConfig.psm1", "New-SupplementalWDACConfig.psm1", "New-DenyWDACConfig.psm1", "Set-CommonWDACConfig.psm1", "New-KernelModeWDACConfig.psm1", "Invoke-WDACSimulation.psm1", "Get-CommonWDACConfig.psm1") # Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export. FunctionsToExport = @("New-WDACConfig", "Remove-WDACConfig", "Deploy-SignedWDACConfig", "Confirm-WDACConfig", "Edit-WDACConfig", "Edit-SignedWDACConfig", "New-SupplementalWDACConfig", "New-DenyWDACConfig", "Set-CommonWDACConfig", "New-KernelModeWDACConfig", "Invoke-WDACSimulation", "Get-CommonWDACConfig") # Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export. CmdletsToExport = @("New-WDACConfig", "Remove-WDACConfig", "Deploy-SignedWDACConfig", "Confirm-WDACConfig", "Edit-WDACConfig", "Edit-SignedWDACConfig", "New-SupplementalWDACConfig", "New-DenyWDACConfig", "Set-CommonWDACConfig", "New-KernelModeWDACConfig", "Invoke-WDACSimulation", "Get-CommonWDACConfig") # Variables to export from this module VariablesToExport = '*' # Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export. AliasesToExport = @() # DSC resources to export from this module # DscResourcesToExport = @() # List of all modules packaged with this module # ModuleList = @() # List of all files packaged with this module FileList = @('WDACConfig.psd1', 'New-WDACConfig.psm1', 'Deploy-SignedWDACConfig.psm1', 'Remove-WDACConfig.psm1', "Confirm-WDACConfig.psm1", "Edit-WDACConfig.psm1", "Edit-SignedWDACConfig.psm1", "New-SupplementalWDACConfig.psm1", "Resources.ps1", "ArgumentCompleters.ps1", "New-DenyWDACConfig.psm1", "Set-CommonWDACConfig.psm1", "New-KernelModeWDACConfig.psm1", "WDAC Policies\DefaultWindows_Enforced_Kernel.xml", "WDAC Policies\DefaultWindows_Enforced_Kernel_NoFlights.xml", "Invoke-WDACSimulation.psm1", "Resources2.ps1", "Get-CommonWDACConfig.psm1") # Private data to pass to the module specified in RootModule/ModuleToProcess. This may also contain a PSData hashtable with additional module metadata used by PowerShell. PrivateData = @{ PSData = @{ # Tags applied to this module. These help with module discovery in online galleries. Tags = @('WDAC', 'Windows-Defender-Application-Control', 'Windows', 'Security', 'Microsoft', 'Application-Control', 'MDAC', 'Application-Whitelisting', 'BYOVD') # A URL to the license for this module. LicenseUri = 'https://github.com/HotCakeX/Harden-Windows-Security/blob/main/LICENSE' # A URL to the main website for this project. ProjectUri = 'https://github.com/HotCakeX/Harden-Windows-Security/wiki/WDACConfig' # A URL to an icon representing this module. IconUri = 'https://raw.githubusercontent.com/HotCakeX/Harden-Windows-Security/main/WDACConfig/icon.png' # ReleaseNotes of this module ReleaseNotes = @" ## Version 0.2.0 1. Added WDAC Simulation using the new Invoke-WDACSimulation Cmdlet 2. Added Get-CommonWDACConfig Cmdlet dedicated only to querying the User Configs and reading them. Set-CommonWDACConfig Cmdlet is only for storing User Configurations. 3. Eliminated the need for an extra reboot in New-KernelModeWDACConfig Cmdlet. From now on, only one reboot is required and that's only during the Audit mode. For deploying the Enforced mode policy, the module replaces the Audit mode policy with the new enforced mode and it instantly becomes operative. 4. Improved the argument completers of the Set-CommonWDACConfig Cmdlet by showing GUI for file picking. 5. Added new parameter to the New-DenyWDACConfig Cmdlet for creating deny rule for Windows Appx apps 6. Improved the parameter usage logic in New-KernelModeWDACConfig Cmdlet ## Version 0.1.9 Improved the New-WDACConfig -MakePolicyFromAuditLogs by accounting for situations where event viewer logs don't contain any files that are no longer on the disk even though user chooses to include them. Added new functionality and cmdlet New-KernelModeWDACConfig, capable of providing complete protection against all BYOVD (Bring Your Own Vulnerable Driver) scenarios Improved the Set-CommonWDACConfig argument completers by showing a file picker GUI when selecting certificates or browsing for custom SignTool.exe path. ## Version 0.1.8 Added Enforced mode SnapBack guarantee for the Edit-WDACConfig and Edit-SignedWDACConfig cmdlets so that even in case of power outage or computer crash, the enforcement will be restored. Improved the code style for better consistency. Added Azure source for version check as the backup endpoint. Full Change log for previous versions are available on Excel online: (Copy and paste the link in your browser if it isn't clickable) https://1drv.ms/x/s!AtCaUNAJbbvIhuVPpPeCHSjl75OqBQ?e=qgvzEt "@ # Prerelease string of this module # Prerelease = '' # Flag to indicate whether the module requires explicit user acceptance for install/update/save # RequireLicenseAcceptance = $false # External dependent modules of this module # ExternalModuleDependencies = @() } # End of PSData hashtable } # End of PrivateData hashtable # HelpInfo URI of this module HelpInfoURI = 'https://github.com/HotCakeX/Harden-Windows-Security/wiki/WDACConfig' # Default prefix for commands exported from this module. Override the default prefix using Import-Module -Prefix. # DefaultCommandPrefix = '' } |