If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: oddvar.moe - Oddvar Moe's Blog  Notes .

site address: oddvar.moe redirected to: oddvar.moe

site title: Oddvar Moe's Blog Notes from My adventures with Windows security

Our opinion (on Friday 21 August 2026 21:56:20 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=Notes from My adventures with Windows security;

Headings (most frequently used words):

applocker, oddvar, the, to, moe, blog, bypass, on, lenovo, machines, curious, case, of, mfgstat, zip, small, discovery, about, bypassing, as, an, admin, doing, pentesteracademy, red, team, lab, temp, orary, constrained, language, mode, in, trustedsec, oh, yeah, making, sure, that, local, rules, are, removed, persistence, using, universal, windows, platform, apps, appx, for, admins, does, it, work, another, way, get, system, shell, assistive, technology, posts, navigation,

Text of the page (most frequently used words):
applocker (41), this (18), the (18), #windows (17), that (17), oddvar (16), moe (15), and (13), posted (11), #bypass (11), tagged (10), continue (10), reading (10), mvp (10), 2018 (10), security (10), about (9), with (9), for (8), comments (7), can (7), research (6), persistence (6), admin (6), comment (5), blog (5), when (5), jul (5), are (5), rules (5), part (5), team (5), red (5), case (5), have (4), com (4), microsoft (4), from (4), while (4), blogpost (4), admins (4), work (4), apps (4), using (4), two (4), local (4), trustedsec (4), oct (4), temp (4), lab (4), was (4), discovery (4), lenovo (4), machines (4), write (3), twitter (3), software (3), system (3), thought (3), technology (3), thing (3), lot (3), doing (3), does (3), appx (3), technique (3), will (3), different (3), system32 (3), sep (3), making (3), sure (3), removed (3), user (3), you (3), constrained (3), out (3), bypassing (3), 2019 (3), study (3), website (2), required (2), content (2), log (2), sign (2), subscribed (2), subscribe (2), wordpress (2), now (2), other (2), posts (2), currentversion (2), binary (2), start (2), during (2), logon (2), some (2), time (2), another (2), way (2), get (2), shell (2), assistive (2), see (2), used (2), post (2), has (2), all (2), hacking (2), autoruns (2), techniques (2), reg (2), add (2), hkcu (2), cortana_1 (2), 17134_neutral_neutral_cw5n1h2txyewy (2), cmd (2), exe (2), universal (2), platform (2), tweet (2), https (2), oddvarmoe (2), status (2), 996147947975962624 (2), leave (2), started (2), yeah (2), tmp (2), powershell (2), orary (2), language (2), mode (2), pentesteracademy (2), first (2), uses (2), back (2), feb (2), ads (2), made (2), small (2), curious (2), mfgstat (2), zip (2), 2025 (2), notes (2), adventures (2), waybackmachine (2), hardening (2), name, email, loading, collapse, bar, manage, subscriptions, view, site, reader, report, privacy, already, account, join, subscribers, powered, search, linkedin, facebook, older, navigation, manipulate, hkey_local_machine, accessibility, ats, magnifier, startexe, run, pressing, winkey, plus, zoom, load, webdav, also, webbrowser, browse, desired, link, runs, command, uac, prompt, screen, finally, had, protect, servers, prevent, certain, things, want, over, what, sort, gives, everyone, pros, cons, remember, administrator, rights, achieved, uwp, debugger, options, not, visible, approaches, exists, registry, keys, listed, below, starts, cortana, app, packagedappxdebug, classes, activatableclasses, package, debuginformation, cortanaui, appxy7vb4pc2dr3kc93kfc509b1d0arkfb2x, mca, debugpath, just, quick, forgot, long, ago, one, issue, someone, gets, access, box, they, create, combined, group, policy, explained, here, job, announced, derbycon, stage, lolbins, talk, really, huge, truly, feel, lucky, such, amazing, talented, people, right, before, summer, vacation, year, former, clm, done, normal, without, privs, change, point, location, allows, execution, scripts, defined, new, environment, variables, set, profit, background, covers, discovered, digging, further, into, teaming, review, pentester, academy, got, possibility, try, thanks, nikhil, mittal, wanted, experiences, fun, learned, stuff, along, road, would, useful, use, host, enabled, gui, briefly, discussed, goal, prepping, session, little, special, turns, files, under, many, cases, default, ruleset, machine, deployed, logs, may, minor, regarding, writeable, file, inside, folder, present, initially, found, only, handful, but, seems, affects, variants, since, abused, msitpros, previous, blogs, ultimate, list, real, whitelisting, attempt, articles, presentations, home, menu, skip,


Text of the page (random words):
oddvar moe s blog notes from my adventures with windows security skip to content menu home about presentations articles applocker case study applocker case study part 1 applocker case study part 2 applocker hardening part 1 applocker hardening part 2 applocker for admins does it work bypassing applocker as an admin applocker making sure that local rules are removed real whitelisting attempt using applocker ultimate applocker bypass list previous blogs msitpros waybackmachine moe am waybackmachine oddvar moe s blog notes from my adventures with windows security applocker bypass on lenovo machines the curious case of mfgstat zip posted on 3 jul 2025 3 jul 2025 by oddvar moe mvp this blogpost is about a minor discovery i made regarding a writeable file inside the windows folder that is present on lenovo machines initially when i found it i thought it was only a handful of lenovo machines but it seems as if this affects all variants since this can be abused as an applocker continue reading applocker bypass on lenovo machines the curious case of mfgstat zip tagged ads applocker bypass research security technology windows 11 comments a small discovery about applocker posted on 29 may 2019 by oddvar moe mvp while i was prepping for a session a while back i made a a little special discovery about applocker turns out that the files that applocker uses under c windows system32 applocker can be used in many cases to bypass a default applocker ruleset when a machine is deployed and the first user logs in that user will continue reading a small discovery about applocker tagged ads applocker bypass research 1 comment bypassing applocker as an admin posted on 1 feb 2019 1 feb 2019 by oddvar moe mvp i thought it would be useful to have a blog post about two different techniques you can use to bypass applocker if you are an admin on a host that has applocker enabled the first technique that uses the gui was briefly discussed in a tweet i posted a while back https twitter com oddvarmoe status 996147947975962624 my goal with this continue reading bypassing applocker as an admin tagged applocker bypass persistence research security 4 comments doing the pentesteracademy red team lab posted on 25 oct 2018 25 oct 2018 by oddvar moe mvp this is my review of the pentester academy red team lab i got the possibility to try out the red team lab thanks nikhil mittal and i wanted to write my experiences with it this was a lot of fun and i learned a lot of stuff along the road it started out with a continue reading doing the pentesteracademy red team lab tagged hacking red teaming leave a comment temp orary constrained language mode in applocker posted on 6 oct 2018 by oddvar moe mvp tl dr done as a normal user without admin privs change temp tmp to point to a location that allows execution of scripts defined by applocker start powershell with the new environment variables that you set for temp tmp and profit background this blogpost covers a technique i discovered when digging further into applocker to bypass powershell constrained continue reading temp orary constrained language mode in applocker tagged applocker bypass clm research security windows 3 comments trustedsec oddvar oh yeah posted on 5 oct 2018 by oddvar moe mvp as i announced at derbycon on stage during my lolbins talk i have now started to work for trustedsec to me this is really huge and i truly feel lucky to be a part of such an amazing team of talented people right before my summer vacation this year me and some of my former continue reading trustedsec oddvar oh yeah tagged job security trustedsec leave a comment applocker making sure that local rules are removed posted on 28 sep 2018 by oddvar moe mvp this is just a quick blogpost about a thing i forgot to write about a long time ago one issue with applocker is that when someone gets admin access on a box they can create local applocker rules that will be combined with the group policy applocker rules this is explained in this tweet here https twitter com oddvarmoe status 996147947975962624 continue reading applocker making sure that local rules are removed tagged applocker security windows 2 comments persistence using universal windows platform apps appx posted on 6 sep 2018 7 sep 2018 by oddvar moe mvp tl dr persistence can be achieved with appx uwp apps using the debugger options this technique will not be visible by autoruns two different approaches exists registry keys listed below are the two techniques for two different apps that starts at logon cortana app reg add hkcu software microsoft windows currentversion packagedappxdebug microsoft windows cortana_1 10 7 17134_neutral_neutral_cw5n1h2txyewy d c windows system32 cmd exe or reg add hkcu software classes activatableclasses package microsoft windows cortana_1 10 7 17134_neutral_neutral_cw5n1h2txyewy debuginformation cortanaui appxy7vb4pc2dr3kc93kfc509b1d0arkfb2x mca v debugpath d c windows system32 cmd exe continue reading persistence using universal windows platform apps appx tagged autoruns bypass hacking persistence research security windows 4 comments applocker for admins does it work posted on 27 jul 2018 by oddvar moe mvp a thing i see a lot is that applocker is used to protect servers and prevent admins from doing certain things in this post i want to go over what sort of security this gives so that everyone can see pros and cons a thing to remember is that an administrator has all the rights continue reading applocker for admins does it work tagged applocker security windows 1 comment another way to get to a system shell assistive technology posted on 23 jul 2018 25 jul 2018 by oddvar moe mvp tl dr manipulate hkey_local_machine software microsoft windows nt currentversion accessibility ats magnifier startexe to run other binary when pressing winkey and plus to zoom can load binary from webdav and also start webbrowser and browse to desired link runs command as system during uac prompt and logon screen i have thought a while about this blogpost and finally had some time to continue reading another way to get to a system shell assistive technology tagged persistence research 4 comments posts navigation older posts facebook linkedin twitter search for website powered by wordpress com subscribe subscribed oddvar moe s blog join 40 other subscribers sign me up already have a wordpress com account log in now privacy oddvar moe s blog subscribe subscribed sign up log in report this content view site in reader manage subscriptions collapse this bar loading comments write a comment email required name required website
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)

Verified site has: 35 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Server nginx
Date Fri, 21 Aug 2026 21:56:20 GMT
Content-Type text/html
Content-Length 162
Connection keep-alive
Location htt????/oddvar.moe/
Alt-Svc clear
Server-Timing a8c-cdn, dc;desc=cdg, cache;desc=BYPASS;dur=0.0
HTTP/2 200
server nginx
date Fri, 21 Aug 2026 21:56:20 GMT
content-type text/html; charset=UTF-8
strict-transport-security max-age=31536000
vary Accept-Encoding
x-hacker Want root? Visit join.a8c.com/hacker and mention this header.
host-header WordPress.com
link <htt????/public-api.wordpress.com/wp-json/?rest_route=/sites/oddvardotmoe.wordpress.com>; rel= htt????/api.w.org/
link <htt????/wp.me/9lQpG>; rel=shortlink
vary accept, content-type, cookie
last-modified Sat, 08 Aug 2026 23:30:53 GMT
cache-control max-age=300, must-revalidate
x-nananana Batcache-Set
content-encoding gzip
x-ac 11.cdg _dca STALE
alt-svc clear
server-timing a8c-cdn, dc;desc=cdg, cache;desc=STALE;dur=5.0

Meta Tags

title="Oddvar Moe's Blog Notes from My adventures with Windows security"
charset="UTF-8"
name="viewport" content="width=device-width, initial-scale=1"
name="robots" content="max-image-preview:large"
name="google-site-verification" content="6QXPAbbHfj1atkzKmV3MBV43nV-Ppt-bDhAdoSYCB7Q"
name="generator" content="WordPress.com"
property="og:type" content="website"
property="og:title" content="Oddvar Moe's Blog"
property="og:description" content="Notes from My adventures with Windows security"
property="og:url" content="htt????/oddvar.moe/"
property="og:site_name" content="Oddvar Moe's Blog"
property="og:image" content="htt????/s0.wp.com/i/blank.jpg?m=1383295312i"
property="og:image:width" content="200"
property="og:image:height" content="200"
property="og:image:alt" content=""
property="og:locale" content="en_US"
name="theme-color" content="#333333"
name="description" content="Notes from My adventures with Windows security"
id="bilmur" property="bilmur:data" content="" data-provider="wordpress.com" data-service="simple" data-site-tz="Etc/GMT-0" data-custom-props='{"enq_jquery":"1","enq_wp-polyfill":"1","logged_in":"0","wptheme":"pub\/lodestar","wptheme_is_block":"0"}'

Load Info

page size196361
load time (s)0.048721
redirect count1
speed download1227500
server IP 192.0.78.25
* all occurrences of the string "http://" have been changed to "htt???/"