{"adoption": {"forks": 362, "observed_at": "2026-08-28T04:06:11.666451+00:00", "stars": 2081}, "canonical_url": "https://ross.abutalabs.com/products/ultimateapplockerbypasslist", "card": {"archived": false, "artifact_type": "dataset", "description": "The goal of this repository is to document the most common techniques to bypass AppLocker. ", "domain": ["security", "penetration-testing", "windows"], "enriched": true, "function": ["security", "penetration-testing", "vulnerability-scanning"], "health_score": 20, "homepage": null, "language": "PowerShell", "license": null, "license_family": "other", "maturity": "maintenance", "member_repos": ["api0cradle/UltimateAppLockerByPassList"], "name": "api0cradle/UltimateAppLockerByPassList", "platform": ["windows", "cli"], "pushed_at": "2023-09-11T20:43:25+00:00", "repo": "api0cradle/UltimateAppLockerByPassList", "stars": 2081, "tags": ["applocker", "bypass-techniques", "red-team", "blue-team", "purple-team", "powershell", "defense-evasion", "yml"], "topics": ["applocker", "bypass", "awl", "rules", "redteam", "blueteam", "purpleteam"], "urls": [], "use_cases": ["find ways to bypass AppLocker default rules during a red team engagement", "test whether our AppLocker policy blocks known bypass techniques", "get a list of AppLocker bypasses in YML to feed into automated tooling", "harden AppLocker rules by blocking common bypass methods", "learn how insecure default AppLocker configurations are", "find DLL execution techniques that evade application whitelisting"], "what_it_is": "A curated collection of documented AppLocker bypass techniques for Windows, organized into verified, unverified, generic, and DLL-execution lists in Markdown and reusable YML formats. It also includes sample AppLocker block policies to help teams harden their configurations.", "when_to_avoid": ["you need an automated bypass tool rather than documentation of techniques", "you are hardening macOS or Linux application controls", "you need actively maintained exploit code with guaranteed updates"], "when_to_choose": ["you are doing red team or purple team work against Windows AppLocker", "you need a reference list of known application whitelisting bypasses", "you are a defender validating or hardening AppLocker block rules"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/ultimateapplockerbypasslist", "repo": "api0cradle/UltimateAppLockerByPassList", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:11.666451+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:55:56.787978+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "d4ca3d3042a4262bc7295ad53e60f609d637165207e9b3fdb0803e240096c38a", "fetched_at": "2026-08-28T04:06:11.666451+00:00", "kind": "readme", "missing": false, "url": "https://github.com/api0cradle/UltimateAppLockerByPassList"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3340, "days_push": 1087, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}