I will bypass Windows Defender in this video by obfuscating an open-source solution file and then compiling the executable. I will use invisibility cloak, defender check, and simple find and replace to show you how to get a known bad binary past Windows Defender. If you want to learn real red team bypass techniques this will show a very effective method to defeat endpoint detection and response (EDR).
Invisibility Cloak:
https://github.com/h4wkst3r/InvisibilityCloak
Defender Check:
https://github.com/matterpreter/DefenderCheck
Visual Studio Community Edition:
https://visualstudio.microsoft.com/vs/community/
Rubeus
https://github.com/GhostPack/Rubeus
FollowMe:
Twitter @BriPwn
-~-~~-~~~-~~-~-
Please watch: "Red Team Tips February 1st: OPSEC Safe Active Directory Enumeration with SilentHound "
https://www.youtube.com/watch?v=MRLZO17ZrmA
-~-~~-~~~-~~-~-
Download
0 formats
No download links available.
Defeating Windows Defender Obfuscating Open Source Tools | NatokHD