Skip to content

v2026.09.26.001: Event 7045 allow-list for Claude, ChatGPT/Codex and Malwarebytes - #8

Open
cdburgess75 wants to merge 4 commits into
mainfrom
fix/7045-allowlist-ai-apps
Open

cdburgess75 wants to merge 4 commits into
mainfrom
fix/7045-allowlist-ai-apps

Conversation

@cdburgess75

@cdburgess75 cdburgess75 commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Do not merge until the branch has had one real Windows run. Merging to main puts this on every endpoint within about 8 hours. HOST-F1 at CustomerF is the obvious test box, since it produced the events. Steps are below.

Why

Customer F's first ShellKnight run (HOST-F1, 2026-09-26) scored F (0/100) on 10 IOCs. Eight of them were Event 7045 service installs by legitimate software that re-registers its services on every update:

Service Path Count
Claude C:\Program Files\WindowsApps\Claude_<ver>_x64__pzs8sxrjxfjjc\app\resources\cowork-svc.exe 3 versions
ChatGPT C:\Program Files\WindowsApps\OpenAI.Codex_<ver>_x64__2p2nqsd0c76g0\app\resources\codex-windows-sandbox-service.exe 2 versions
MBAMProtection, MBAMWebProtection, Malwarebytes Anti-Exploit C:\WINDOWS\system32\drivers\mbam.sys, mwac.sys, mbae.sys 3 drivers, each 3x

Each IOC costs 15 points, capped at 50. The other two IOCs were a per-user ScreenConnect client under AppData. They are left alone here, because a human needs to confirm whose it is.

What changes

Everything is allowed by what cannot be borrowed, never by the service name:

  • Store apps: matched by package folder. The rule is anchored at X:\Program Files\WindowsApps\ and must end in the publisher ID. WindowsApps is writable only by the system, and the publisher ID suffix is determined by the package's signing certificate. A different publisher's package, or a folder named WindowsApps anywhere else, does not match.
  • Malwarebytes drivers: new $knownGoodSvcDrivers table. They install to a bare system32\drivers path with no vendor folder, so the table requires the service name and the exact driver file in the real Windows driver directory. It accepts the C:\WINDOWS\..., \SystemRoot\..., \??\C:\... and bare System32\... forms. That is stronger than the name-only entries used for the Avira drivers: mbam.sys copied to C:\evil\system32\drivers\, or registered under another service name, still alerts.
  • Housekeeping. Version v2026.09.26.001, with entries in both changelogs. The diff adds no non-ASCII bytes and the AST parse shows 0 errors.

Scoring

  • Upward only. Devices running these apps stop losing up to 50 points to them, and no device loses points.
  • Alerts: Battlefield resolves the matching IOC alerts once a later run stops reporting them.

Tests

New tests/Test-Svc7045Allowlist.ps1, in the style of Test-EngineScope.ps1, runs the Event log IOC block verbatim under StrictMode 2 with Get-WinEvent mocked. It has 29 checks:

  • Allowed: CustomerF's eight events verbatim, the other driver path forms, case-insensitive matching, OpenAI's ChatGPT desktop package (same publisher), and two existing entries (CentraStage, googleupdater) as regression guards.
  • Must still alert (13 look-alikes):
    • "Claude" or "ChatGPT" outside WindowsApps;
    • another publisher ID, including a suffixed one;
    • a WindowsApps folder elsewhere or outside Program Files;
    • a Malwarebytes name with the wrong or relocated driver;
    • mbam.sys under another name;
    • an unknown service.
  • Combined: CustomerF's eight events plus one unknown service give exactly one IOC.

Results:

  • All five test scripts pass.
  • Against current main, the new test fails 14 assertions. Each of these weakenings fails it too:
Mutation Failures
WindowsApps rule not anchored 2
Publisher ID not required 2
Driver folder not anchored 1
Malwarebytes allowed by name only 4
Service names Claude/ChatGPT allowed 7

This is a mock test, not a Windows run.

Before merging: one real run

On HOST-F1, through Datto, run the branch the same way PR #4 was tested on HOST-A3. The branch URL is https://raw.githubusercontent.com/cdburgess75/ShellKnight/fix/7045-allowlist-ai-apps/ShellKnight.ps1.

Then check the newest log:

  • No Event log IOC skipped line.
  • No Event 7045 (Service Install) suspicious line for Claude, ChatGPT or MBAM.
  • SECURITY GRADE rises accordingly.

Battlefield should show the same device with those alerts resolved.

Left alone

  • The per-user ScreenConnect client on a user's PC: someone needs to confirm whose server it talks to.
  • Name-only allow-list entries: the Avira, rtp* and NordVPN names could move to the new name-plus-path table.

🤖 Generated with Claude Code

…Malwarebytes

CustomerF's first run (HOST-F1) scored F (0/100) on 10 IOCs, 8 of
them Event 7045 service installs by legitimate software that re-registers its
services on every update: Claude's cowork-svc and OpenAI's Codex sandbox
service (Microsoft Store packages) and three Malwarebytes kernel drivers.

Allowed by what cannot be borrowed, never by service name:
- Store apps by package folder, anchored at X:\Program Files\WindowsApps and
  ending in the publisher ID the signing certificate determines.
- Malwarebytes drivers by service name AND exact driver file in the real
  system32\drivers directory (new $knownGoodSvcDrivers).

Look-alikes (a service named "Claude", another publisher's package, a
WindowsApps folder elsewhere, mbam.sys under another name or directory)
still raise the IOC. New tests/Test-Svc7045Allowlist.ps1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

cdburgess75 and others added 3 commits September 26, 2026 16:19
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…gess75/ShellKnight into fix/7045-allowlist-ai-apps

# Conflicts:
#	docs/adr/0006-device-identity-and-site-assignment.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant