In many organizations, it seems that they conduct some kind of countermeasures such as restricting communication with C2 and authority of client’s account to reduce the risk in the case of malicious program invade into theirs organization network by such as targeted attacks. As a way to mitigate that risks, there are restrictions on the operations using registry in Windows and applications launched by AppLocker. However, also there are ways to bypass these security functions. I would like to show some bypass approaches, and please use these as a reference for mitigation the risks in your organization. In this presentation, specifically, I will introduce the methods how to run ‘Powershell without Powershell’ which bypasses AppLocker released in 2016, Powershell by exploitation less common AppLocker’s vulnerability, and an alternative method in situation of Internet Explorer restricted (not using another browsers), and so on, these are from penetration test experiences.