How Hackers use PowerShell to EVADE Anti-Virus Software

preview_player
Показать описание
One of the main jobs of any penetration tester / red teamer is to evade Anti-Virus / EDR solutions on the targeted systems. While PowerShell is not applicable to each case, it is extremely flexible when we can utilize it.

SUPPORT MY WORK BY BECOMMING PATREON
---------------------------------------------------

LINKS
---------------------------------------------------

FOLLOW ME
---------------------------------------------------
Рекомендации по теме
Комментарии
Автор

Thanks for the video!
I love using Invoke-Obfuscation for obfuscating my payloads, they bypass w defender as well.

Tathamet
Автор

Love your videos! If I can make a suggestion it would be to pronounce your Ls more. Right now they sound a lot like a W. English isn't my first language either making it hard to understand sometimes without subtitles :(

probablypablito
Автор

Thanks a lot for the video, I think i understand your way of teaching. Gracias. I turned on notifs

hackerfate
Автор

Cool mate hope more vedios come about what after this without defender geting caught

firosiam
Автор

How can we do privilege accelation using PowerShell reverse shell. Please make a video on it

callduty
Автор

Sir, Do you give any courses ? I would absorb your teachings ❤

Kingddos
Автор

Bro, We need How to bypass more av solutions like avast or Kaspersky. Love Yours Videos 💌

tanmoygoswami
Автор

love the videos bro, but there is a search box in the top right corner of process hacker, and every time you manually try to find a process id or name i scream at my computer : P

**after messing with rastamouse bypass, it seems like you can copy and paste it in powershell (it will flag as malicious), then close powershell and open powershell again, paste the same bypass again and it works .. Can anyone confirm the same behavior on their env?

austinmurphy
Автор

why you need turn off cloud-deliveried protection ??

taileuc
Автор

It appears this does not work as of today. Your mileage may vary.

bobg