Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Fancy Defender evasion? Yet another method, nearly bare hands: 1. Export CurrentControlSet to a file 2. Edit path in a file 3. Import a file as new ControlSet 4. Change "Select" values to new one 5. Reboot 6. Enjoy 😎 A side effect of my "Registry internals" session yesterday 😅

74,059 Aufrufe • vor 2 Jahren •via X (Twitter)

11 Kommentare

Profilbild von Grzegorz Tworek
Grzegorz Tworekvor 2 Jahren

BTW if you think about responsible disclosure, the answer is quite simple: @msftsecresponse closes immediately reports related to Defender if you do not provide "Short explanation on how an attacker could use the information to exploit another user remotely".

Profilbild von imag0r
imag0rvor 2 Jahren

You can get around pretty much all AVs this way. Addressing it would be super expensive performance wise. There’s really no good way to stop admins from doing nasty things.

Profilbild von Grzegorz Tworek
Grzegorz Tworekvor 2 Jahren

One RegNotifyChangeKeyValue() watching the Select key.

Profilbild von Daniel Mielczarek
Daniel Mielczarekvor 2 Jahren

is that method work only on admin account or non-priveleged also?

Profilbild von Grzegorz Tworek
Grzegorz Tworekvor 2 Jahren

Admin only, due to two reasons: 1. RegSaveKey() / RegRestoreKey() restrictions, 2. Permissions on HKLM\SYSTEM and HKLM\SYSTEM\Select

Profilbild von Advanced Persistent Dread
Advanced Persistent Dreadvor 2 Jahren

@UK_Daniel_Card really cool!

Profilbild von Advanced Persistent Dread
Advanced Persistent Dreadvor 2 Jahren

could we run our own program instead? e.g. nsmpeng.exe ? snd would that have additional benefits?

Profilbild von Grzegorz Tworek
Grzegorz Tworekvor 2 Jahren

Sure. You can add your own service after restoring the key. Or just edit paths in the binary file. Whatever is easier for you.

Profilbild von spencer
spencervor 2 Jahren

Lol nice

Profilbild von Br3akp0int
Br3akp0intvor 2 Jahren

@Sug4r7 this is awesome! I also have similar research in this persistence topic and I’m planning to release it later this aug.but I might release it soon because of this great research! 😊👍

Profilbild von Grzegorz Tworek
Grzegorz Tworekvor 2 Jahren

@Sug4r7 And what about publishing your research in parts? :)

Ähnliche Videos