Powerful batch script to dismantle complete windows defender protection and even bypass tamper protection ..Disable Windows-Defender Permanently...Hack windows. POC
Usage:
- Run run.bat and enter the direct link of your malware
- Run the script "Defeat-Defender.bat". It will ask for Admin Permission. If permission is Granted The script will work Silently and dismantle all protection...
After it got admin permission it will disable the defender
- PUAProtection
- Automatic Sample Submission
- Windows FireWall
- Windows Smart Screen(Permanently)
- Disable Quickscan
- Add exe file to exclusions in defender settings
- Disable Defender Notification (Added Recently)
- Disable UAC(Reboot Required)
- Disable Ransomware Protection
- Disable TaskManager
- Disable registry etc...
Proof-Of-Concept
Bypassing Windows-Defender Techniques :
Recently Windows Introduced a new Feature called "Tamper Protection".Which Prevents the disable of real-time protection and modifying defender registry keys using PowerShell or cmd...If you need to disable real-time protection you need to do it manually...But We will disable Real-Time Protection using NSudo without triggering Windows Defender
Running Defeat-Defender Script
Warning
This Script will completely Disable Windefend Services. And also it is very difficult to revert the changes. Think twice before you run the script
Behind The Scenes :
When the Batch file is executed it ask for admin permissions. After getting admin privilege it starts to disable windows defender's real-time protection, firewall, SmartScreen, and starts downloading our backdoor from the server and it will be placed in the startup folder. The backdoor will be executed after it has been downloaded from the server...And will be started whenever the system starts...
إرسال تعليق