Hacking Windows 11 SE

preview_player
Показать описание
Today I am going to show you how to hack the Windows 11 SE edition to run .exe and sideload .dll applications. The way the SE edition works is almost no different to how the Windows 10 S Mode does. It uses Code Integrity policies within «App Control for Business» with a little twist. Fundamentally, though, the new S Mode is very different to the old S Mode.

*DIY:*
1. Reboot into recovery/Windows PE. To reboot into recovery, use the ROFT command: shutdown -r -o -f -t 0
2. Mount ESP (EFI System Partition), I'll refer to it as W:.
3. Locate and enter the W:\EFI\Microsoft\Boot\CIPolicies\Active directory.
4. Wipe all the code integrity policies - the *.cip files.
5. Profit!

*Links:*

*Password:*
mysubsarethebest

*Timestamps:*
0:00 - Intro
0:19 - About Windows 11 SE
0:53 - Acquiring the image
2:01 - Installing
3:29 - The «E Mode»
5:19 - Early ideas
6:17 - Audit mode
7:52 - Local account
10:04 - Device Guard single-policy files
10:52 - Regeneration
11:23 - Multi-policy files
12:16 - Success
13:00 - Finishing the install
13:51 - Final product
14:52 - Outro

Hope you have a great day!

#endermanch #experiments #windows
Рекомендации по теме
Комментарии
Автор

I love how Microsoft made a second edition to block your method out and then you came up with another one almost instantly. Can't wait for that second video!

ChristOurLife
Автор

2:42 ah, my favorite cmd commands, "ass letter w" and "ass letter c"

MiningJack
Автор

Let's just hope YouTube doesn't take this video title too seriously

HelloandMore
Автор

Microsoft: "This Windows SE prevents users from launching apps and has imcredibly tight security!"
Also Microsoft: "So here is the documentation on how to remove SE modes from Windows SE..."

BattyBest
Автор

3:14 I like how the limbo music stops when the OS boots

Jaldolf.PlayzGamez
Автор

Sick! As a MSP agent, this will be very useful to know in certain legit support scenarios and will likely save a lot time and money for me and my customers.

tomrd
Автор

The requirement to login with a Microsoft account could be related to the build being an insider preview, Microsoft accounts are required on those builds if memory serves. So it could be worth having a quick look at a normal 22621 build of SE.

SirWobbyTheFirst
Автор

I think audit mode is unlocked because it makes deploying easier, especially on a lot of machines. Also most users don’t know about audit mode, even some that know how to break the system so.. maybe Microsoft just expected people to not know? Hard to tell honestly

graygghost
Автор

3:17
LIMBO.
[key moves]
Yo was it green?
[dies]
damn it

Space_US
Автор

i can't stop thinking of how it is a coincidence that all of your video's music are used in really hard GD levels.

cubeengineer
Автор

here is what i thought after i said some things in live premiere chat:
-1. I found out that windows 10 s name is streamlined, so can w11 se be Windows 11 -_-Streamlined Education-_- ?- (how did i miss that image faq in video?)
, i watched video from start to end (during premiere), i haven't paid attention to it)
2. I must have thought wrong, and se default could be not exact the install that is made from uup by changing config ini file or upgrading from pro edition, but its unique iso that has probably wallpapers and more uwp apps out of box (i noticed that inbox apps iso has Minecraft education edition, it would have appear in se installs in laptops that has se preinstalled such as surface laptop se)

3. at the very end of premiere, i talked about how do you (not enderman specifically) think that windows rt can run system components such as internet explorer, explorer, legacy calculator (if it does have) and notepad if running non uwp exes are not allowed? (although i may know how is that possible)
(the comment will be edited)

hrpG_tCL-l_
Автор

Wait, wouldn't the invalid microsoft account trick for creating a local account have worked in this scenario?

MigProPlayer
Автор

3:18 You didn't have to sync it SO FRICKING WELL!! That is such high quality editing, to be able to cut out the exact right parts to make the video sync, nice job! Also, this itself is really impressive, you must know at least something about C.




🔑 🔑
🔑 🔑
🔑 🔑
🔑 🔑

Retro_
Автор

we should hope that Microsoft doesn't take down this video

TheWanderingTraderm
Автор

I had Windows 11 SE ISO a long time ago. I do not remember what build it is, but it is an oldest build that i have found. Also, the problem with apps still working was in the oldest build, too, but it had included fix file in the ISO, which turned on "E mode". The Drive C:/ modification is disabled after signing in to microsoft account. Anyways, good video!

定义
Автор

6:58 it's not an oversight; audit mode is generally used to deploy drivers/business apps to all users, so it would make sense why audit mode overrides "E mode".

alwaystrue
Автор

6:38 Not sure if you noticed in the top right corner but there is a warning that the system is not secured. Microsoft probably knows about this vulnerability, but still left it there. I can't say for sure tho, that warning may be caused by something else.

angelbepro
Автор

i never expected enderman, my favorite tech creator, who inspired me to create this channel, to use the limbo theme from funni cube game

DccToon
Автор

Best song in the beginning :) I love Isolation so much!

Shadow.Tech
Автор

For YouTube: What he actually means is that he's debugging Windows SE

Abigblueworld