Because I didn’t find a program to start an application with a given integrity level from “Image File Execution Options”, I wrote runasil.
The following command launches notepad.exe with a low integrity level, instructing notepad to open test.txt:
runasil.exe notepad.exe test.txt
To automatically launch notepad via runasil.exe, using “Image File Execution Options”, create this registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe and create a value debugger equal to “runasil.exe -d” (don’t forget option -d).
You can also specify the integrity level via an option:
- -l for low
- -m for medium
- -h for high
- -s for system
By default, runasil launches the application with a low integrity level.
Don’t forget you need at least Windows Vista to use integrity levels, and that a process can’t create a new process with a higher integrity level than itself.
Download:
MD5: 5B8CE64715903DD7EEF4AF3B89E6E6FD
SHA256: 15841A9D9985E626C5B70B4BC3B2BF2CD68C38102B6BB1D92BA352D19F5C8A65
[…] dropped rights: PsExec StripMyRights 1-defender Running program with specific integrity level: Runasil Chml and […]
Pingback by Ultimate Security List – (TEK) Innovations — Tuesday 16 May 2017 @ 23:39