Did you know, that instead of killing the Windows Defender process, you can remove the signatures (requires local admin privs)?
After that you can do pretty much what you want, e.g. downloading & running mimikatz.
Here is a small PoC, I made for @cyvisory
Low Level Malware Protection
1. Use web proxies 🌉
(proxy awareness in all malware stages is rare)
2. Block executable downloads 🚦
(from unclassified domains; stage 2+ is often executable content)
3. Restrict workstation to workstation communication 🚧
(contains an outbreak)
Look at this slice of awesome. The new Wireshark version in dev (3.3.0) has a packet diagram view.
A fantastic teaching and learning tool! When released, I'll be making pretty extensive use of this in my classes! Great job @geraldcombs and @WiresharkNews team.
Using @github Enterprise?? Want to monitor it for #Security in #AzureSentinel? Itay Argoety, @rubin_mor and I just shared how you can do it!!!
https://t.co/T2mG5JJuNf
Finished my talk for #NahamCon tomorrow, what you can expect:
• Two 0-click account takeovers on popular bug bounty programs
• A common XSS vector in e-mail providers
• A vulnerability in @intigriti's e-mail forwarder
• An #OSINT trick to unmask cybercriminals
• Blind RCE