The mask is not displayed with TDAD on-premises and Windows 10 / 11 (version 22H2)
book
Article ID: 278216
calendar_today
Updated On:
Products
Endpoint Threat Defense for Active Directory
Issue/Introduction
After updating to or installing Windows 10 / 11 (version 22H2), you do not see the obfuscation mask displayed when running reconnaissance commands on an endpoint.
Environment
TDAD Integrated and Standalone versions: 3.6.2.4, 3.6.2.6, and 3.6.2.8 Windows 10 / 11 (version: 22H2)
Cause
TDAD On-premises has not been updated to support newer OSs such as Windows 10 / 11 (version 22H2) and later. Because of this, memory injection will not work, and the mask is not displayed.
Resolution
Update OS support with a new OSConfig.dat file:
Download the updated OsConfig.dat from the article, below
Open the IIS (Internet Information Services) Manager
Select the top-level website hosting TDAD
In the Actions pane under Manage Server click Stop
Open a File Explorer to: C:\Program Files\Symantec\Endpoint Threat Defense for AD\dm_pub\Traps\genFake\ExtraSections
Save a backup copy of OsConfig.dat (it can be removed later when the new file is confirmed working)
Copy the new OsConfig.dat over the existing one
Return to the Actions pane in the IIS Manager and click Start to bring the website back up
Open the TDAD UI (https://<tdad_server>/ui/login) and log in with an Administrator-level account
Update the obfuscation to rebuild files for the endpoints
Click Edit
Select the domain
Click Next 3 times
Change the multiplication factor
Click Next and Save
Wait for AI to complete
Repeat step 11 and set multiplication factor back to the original value
Click Re-Run AI Learning
Select the domain
Click Re-Run
Re-deploy to endpoints
TDAD Integrated:
Reboot SEPM machine
Log in to the SEPM
Check the policy serial number on the relevant group(s)
Ensure the SEP policy serial number has updated on client machines and reboot them (You can wait for the next heartbeat, or force a heartbeat from the client's tray icon)
TDAD Standalone:
If a label is assigned to the endpoint's OU, the deployment should be automatic.
If labels are assigned to specific endpoints, assign the label to those endpoints which have not been previously deployed.
Reboot the endpoints to ensure the updated OS support is applied
Confirm the mask is displayed when running recon commands
NOTE: This process is required to continue using obfuscation masking in an environment where Windows 10 / 11 are upgraded to 22H2. However, the same updated OSConfig.dat file doesn't support Windows 11 22H2 and later versions.