Bruteforcing Windows Defender Exclusions

Поділитися
Вставка
  • Опубліковано 25 лис 2024

КОМЕНТАРІ • 51

  • @RhizGh037
    @RhizGh037 Місяць тому +24

    Thanks John. I like the more technical angle of your videos and not simplifying too much, helps a lot for those of us in the grey zone.

  • @andljoy
    @andljoy Місяць тому +9

    I just tested this and it does indeed work and MDE does not flag anything up. That is not good. Is there a CVE for this ?

  • @infinitivez
    @infinitivez Місяць тому +11

    It's an executable, it has to be calling some set of system calls to get this information (especially if PowerShell has embedded access). I imagine we can create something with a lot less overheard than rerunning the MpCmdRun each time.

  • @400EMP
    @400EMP Місяць тому +2

    Seems a bit pointless if all these are logged (as you said) to Event Viewer. Running a PowerShell command to pull that Event ID with some filtering is likely more stealthy (and accurate) than just generating a process over and over.

  • @Neuer_Alias_erstellen
    @Neuer_Alias_erstellen 25 днів тому +1

    grate vid - you showed a way to detect the defnder cli abuse to but is there a way to avoid the defender log being readable by every user

  • @borgheses
    @borgheses Місяць тому +5

    easy anti cheat has some human readable strings that might be interesting

  • @raimomanninen9579
    @raimomanninen9579 Місяць тому +20

    You can open elevated Powershell window from non-elevated Terminal just by clicking the drop-down menu next to the plus-sign on the tab row and Ctrl+clicking the "Powershell" option.

    • @madmackenzie3459
      @madmackenzie3459 Місяць тому +7

      i still needed admin privelages to do this (win11)

    • @fatedsky6700
      @fatedsky6700 Місяць тому +4

      It might not show a uac on your end, but admin is still required, this is not a uac bypass

    • @raimomanninen9579
      @raimomanninen9579 Місяць тому +7

      @@fatedsky6700 I wasn't saying this was an UAC bypass, just an alternate method to open elevated Powershell window instead of closing the original Terminal window and then opening the elevated one from the Start menu like shown on the video.

    • @fatedsky6700
      @fatedsky6700 Місяць тому +4

      @@raimomanninen9579 oh alright, thanks for the clarification

    • @someoneunknown6894
      @someoneunknown6894 Місяць тому +1

      I've heard there's also `sudo` now on windows 11

  • @rupiec382
    @rupiec382 Місяць тому

    "The exclusions do not bypass security mechanisms; they simply exclude the specified items from static scanning."

  • @JeremyMcMahan
    @JeremyMcMahan Місяць тому

    Thanks for the video on Defender Exclusions! We built a script to check for rogue or unneeded exclusions in Widows Defender after watching. One thing we found: McAfee Antivirus leave its exclusion in place after it's been uninstalled. How big a deal do you think these being left behind is? "c:\program files\mcafee'c:\program files\common files\mcafee'c:\program files (x86)\mcafee'c:\program files (x86)\common files\mcafee'C:\DELL\FD09N'c:\programdata\mcafee"

  • @karim3741
    @karim3741 Місяць тому +2

    Always great content, taking this further using a tool like binfinder from kudaes we can also find processes that are internally excluded by an edr
    Like SYSTEM level svchost processes and crowdstrike 😉

  • @KLEOPATTRAALTHANI
    @KLEOPATTRAALTHANI Місяць тому

    You are my best friend John 🧡🙏🤘🙌👌I appreciate that!!!

  • @Killbot_2000
    @Killbot_2000 Місяць тому

    how long did it take you to know/remember all these windows commands?

  • @simple-security
    @simple-security Місяць тому +2

    how many sigma rules do you need to write to cover off all conditions not detected by a typical edr 😕
    This is where I hope threat hunting query libraries can continue to improve in vendor products. eg. 'run all hunting queries' and get a human and/or robot to look at it.

  • @naderly
    @naderly Місяць тому

    That was amazing!!

  • @ipb4isleep
    @ipb4isleep Місяць тому +1

    why are we bruteforcing windows defender exclusions?

    • @sawbeenn
      @sawbeenn Місяць тому +3

      As said, you would like to load your somewhat malicious files there.

  • @젤리의일상
    @젤리의일상 Місяць тому

    Good John❤

  • @760a
    @760a Місяць тому

    Can you do a tutorial on how to make a windows 11 virtual machine I know how to make one but it's always having issues and urs look good

  • @DePhoegonIsle
    @DePhoegonIsle Місяць тому

    This is why I am in favor of exluding on-access scans, while leaving on-demand/scheduled ones not excluded. X>.>X
    Pretty sure that you'd not get that feedback if it could properly be setup like that. (I've got bitdefender setup to exclude on-access, to several key folders to not slice my face off when I run IDEs for some projects, but leave on-demand intact because I don't code in that style that would trip the stuff.. I just hate the preformance hit.

  • @lxn7404
    @lxn7404 Місяць тому

    I swear I'll unsubscribe if I get an ad during the ad again

  • @HorstSchlaemmer00
    @HorstSchlaemmer00 Місяць тому +4

    Please more blue team (defender) Videos...

  • @ulixir
    @ulixir Місяць тому

    someone is definitely going to try to exploit this but i doubt it'll do damage, it'll probably be patched in a few hours

  • @Toast_d3u
    @Toast_d3u Місяць тому

    Ty

  • @FelipeWlodkowski
    @FelipeWlodkowski Місяць тому +3

    Can someone explain how can this be useful? I'm a new student on this field.

    • @sutsuj6437
      @sutsuj6437 Місяць тому +7

      Once the malware knows what directories are excluded it could just copy itself to that directory and avoid any anti-virus detection.

    • @oshito
      @oshito Місяць тому +2

      This is useful to avoid anti-virus detection when you are now executing the main malware from the loader/dropper.

  • @llllleonllllyt1566
    @llllleonllllyt1566 Місяць тому

    Great vid🔥

  • @joelanzo
    @joelanzo Місяць тому

    Greetings from Africa

  • @VectirR6
    @VectirR6 Місяць тому +2

    you are a PowerShell / cmd mega chad, looks like a guy who code on linux only with keyboard but for windows

  • @darkdagger032
    @darkdagger032 Місяць тому

    That's a nice trick

  • @MrNyto_
    @MrNyto_ Місяць тому

    neat!

  • @THRE3KINGZStudios3kz
    @THRE3KINGZStudios3kz Місяць тому

    Nice! ❤

  • @hilik3186
    @hilik3186 Місяць тому +1

    5:00

  • @GodDamnitTwitch
    @GodDamnitTwitch Місяць тому +2

    12:40 task failed successfully? I guess...

  • @MohammedAli-rn5dp
    @MohammedAli-rn5dp Місяць тому

    👀💪

  • @carsonjamesiv2512
    @carsonjamesiv2512 Місяць тому

    👍

  • @Hartley94
    @Hartley94 Місяць тому

    🙏💯

  • @حسامعلي-ل4ح5ل
    @حسامعلي-ل4ح5ل Місяць тому

    😂😂😂😂😂😂😂😂😂❤😅😅😅ههههههههه

  • @inadad8878
    @inadad8878 Місяць тому

    First

  • @codingwithebooks
    @codingwithebooks Місяць тому

    guys i need help...My laptop fell and got destroyed no money to get a new one...please help me😪