FreeBuf手把手教你构建自定义的Mimikatz二进制文件( 四 )


虽然检测率还没啥太大变化 , 但目前已经可以绕过开启了云保护功能的Windows Defender了:
FreeBuf手把手教你构建自定义的Mimikatz二进制文件
本文插图
链接&资源WinPwn - https://github.com/S3cur3Th1sSh1t/WinPwn
Inspiring Gist - https://gist.github.com/imaibou/92feba3455bf173f123fbe50bbe80781
Mimikatz - https://github.com/gentilkiwi/mimikatz
Mimikatz Features & Detection - https://adsecurity.org/?page_id=1821
DefenderCheck - https://github.com/matterpreter/DefenderCheck
Obfuscating Mimikatz - https://sudonull.com/post/27330-Getting-around-Windows-Defender-cheaply-and-cheerfully-obfuscating-Mimikatz-THunter-Blog
AVCleaner C/C++ obfuscation - https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/&
PEZor - https://iwantmore.pizza/posts/PEzor.html
FreeBuf手把手教你构建自定义的Mimikatz二进制文件
本文插图
FreeBuf手把手教你构建自定义的Mimikatz二进制文件
本文插图
【FreeBuf手把手教你构建自定义的Mimikatz二进制文件】


推荐阅读