1 of 7

Module: Windows Security Model

Robert Wasinger

Arizona State University

2 of 7

Everything is an Object

  • In Windows everything is an object managed by the Object Manager
    • We can see persistent Kernel Objects
      • Winobj
      • Get-Ntobject
      • Get-Nttype
    • We can see transient Kernel Objects
      • Process Explorer
      • WinDbg

3 of 7

Authorization Token Based Model

  • Session Token
    • At log in an initial session is assigned
    • Get-nttoken
    • All processes inherit this token
    • SID: Security Identifier
  • “ntobjectmanager” powershell module
    • Adds several hundred “X-ntY” cmdlets

4 of 7

SIDs - You’re you according to who?

S-1-5-21-3803740410-2989969783-2948458312-1000

SID

Revision Level

Authority

Subathority

RID - Relative Identifier

Several SIDS are well known, 5 is NtAuthority

5 of 7

Access Mask (DAC)

  • Linux has RWX
  • Windows has Access Masks
  • Higher order bits (31-28) hold “Generic Access”
    • GenericRead, GenericWrite, GenericExecute
    • These map to type specific access
  • Get-NtTypeAccess -Type File

6 of 7

Integrity Levels

  • Direct hierarchy - untrusted, low, medium, high, system
  • Minimum Integrity Level required to access specific objects
  • By default, “write up” is enforced

7 of 7

Code Signing