Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Fancy Defender evasion? Yet another method, nearly bare hands: 1. Export CurrentControlSet to a file 2. Edit path in a file 3. Import a file as new ControlSet 4. Change "Select" values to new one 5. Reboot 6. Enjoy 😎 A side effect of my "Registry internals" session yesterday 😅

74,059 görüntüleme • 2 yıl önce •via X (Twitter)

11 Yorum

Grzegorz Tworek profil fotoğrafı
Grzegorz Tworek2 yıl önce

BTW if you think about responsible disclosure, the answer is quite simple: @msftsecresponse closes immediately reports related to Defender if you do not provide "Short explanation on how an attacker could use the information to exploit another user remotely".

imag0r profil fotoğrafı
imag0r2 yıl önce

You can get around pretty much all AVs this way. Addressing it would be super expensive performance wise. There’s really no good way to stop admins from doing nasty things.

Grzegorz Tworek profil fotoğrafı
Grzegorz Tworek2 yıl önce

One RegNotifyChangeKeyValue() watching the Select key.

Daniel Mielczarek profil fotoğrafı
Daniel Mielczarek2 yıl önce

is that method work only on admin account or non-priveleged also?

Grzegorz Tworek profil fotoğrafı
Grzegorz Tworek2 yıl önce

Admin only, due to two reasons: 1. RegSaveKey() / RegRestoreKey() restrictions, 2. Permissions on HKLM\SYSTEM and HKLM\SYSTEM\Select

Advanced Persistent Dread profil fotoğrafı
Advanced Persistent Dread2 yıl önce

@UK_Daniel_Card really cool!

Advanced Persistent Dread profil fotoğrafı
Advanced Persistent Dread2 yıl önce

could we run our own program instead? e.g. nsmpeng.exe ? snd would that have additional benefits?

Grzegorz Tworek profil fotoğrafı
Grzegorz Tworek2 yıl önce

Sure. You can add your own service after restoring the key. Or just edit paths in the binary file. Whatever is easier for you.

spencer profil fotoğrafı
spencer2 yıl önce

Lol nice

Br3akp0int profil fotoğrafı
Br3akp0int2 yıl önce

@Sug4r7 this is awesome! I also have similar research in this persistence topic and I’m planning to release it later this aug.but I might release it soon because of this great research! 😊👍

Grzegorz Tworek profil fotoğrafı
Grzegorz Tworek2 yıl önce

@Sug4r7 And what about publishing your research in parts? :)

Benzer Videolar