Загрузка видео...

Не удалось загрузить видео

На главную

Fancy Defender evasion? Yet another method, nearly bare hands: 1. Export CurrentControlSet to a file 2. Edit path in a file 3. Import a file as new ControlSet 4. Change "Select" values to new one 5. Reboot 6. Enjoy 😎 A side effect of my "Registry internals" session yesterday 😅

74,059 просмотров • 2 лет назад •via X (Twitter)

Комментарии: 11

Фото профиля Grzegorz Tworek
Grzegorz Tworek2 лет назад

BTW if you think about responsible disclosure, the answer is quite simple: @msftsecresponse closes immediately reports related to Defender if you do not provide "Short explanation on how an attacker could use the information to exploit another user remotely".

Фото профиля imag0r
imag0r2 лет назад

You can get around pretty much all AVs this way. Addressing it would be super expensive performance wise. There’s really no good way to stop admins from doing nasty things.

Фото профиля Grzegorz Tworek
Grzegorz Tworek2 лет назад

One RegNotifyChangeKeyValue() watching the Select key.

Фото профиля Daniel Mielczarek
Daniel Mielczarek2 лет назад

is that method work only on admin account or non-priveleged also?

Фото профиля Grzegorz Tworek
Grzegorz Tworek2 лет назад

Admin only, due to two reasons: 1. RegSaveKey() / RegRestoreKey() restrictions, 2. Permissions on HKLM\SYSTEM and HKLM\SYSTEM\Select

Фото профиля Advanced Persistent Dread
Advanced Persistent Dread2 лет назад

@UK_Daniel_Card really cool!

Фото профиля Advanced Persistent Dread
Advanced Persistent Dread2 лет назад

could we run our own program instead? e.g. nsmpeng.exe ? snd would that have additional benefits?

Фото профиля Grzegorz Tworek
Grzegorz Tworek2 лет назад

Sure. You can add your own service after restoring the key. Or just edit paths in the binary file. Whatever is easier for you.

Фото профиля spencer
spencer2 лет назад

Lol nice

Фото профиля Br3akp0int
Br3akp0int2 лет назад

@Sug4r7 this is awesome! I also have similar research in this persistence topic and I’m planning to release it later this aug.but I might release it soon because of this great research! 😊👍

Фото профиля Grzegorz Tworek
Grzegorz Tworek2 лет назад

@Sug4r7 And what about publishing your research in parts? :)

Похожие видео