antonioCoco / ConPtyShell

ConPtyShell - Fully Interactive Reverse Shell for Windows
MIT License
952 stars 158 forks source link

False alarms with Antivirus software #12

Closed rgwebcode closed 1 year ago

rgwebcode commented 1 year ago

Not sure there's anything you can do about it, but the .ps1 file and the .exe files are recognized as malware by some antivirus softwares (unfortunately including my Eset installation).

antonioCoco commented 1 year ago

yeah, i know. Some threat actors have been using this shell and many vendors flagged this as malicious. IMO it's not wise to detect malicious usages of this tool statically, but everyone is free to create detection in the way it prefers. I'm not going to play the cat-and-mouse game for static detection evasion, so if you want to use it on your systems please use exclusions on your AV software. If you need to use this in your red team engagements, well i don't have to tell what you need to do ;)