guardicore / monkey

Infection Monkey - An open-source adversary emulation platform
https://www.guardicore.com/infectionmonkey/
GNU General Public License v3.0
6.62k stars 772 forks source link

Remove ms08_067 exploiter #1327

Closed mssalvatore closed 3 years ago

mssalvatore commented 3 years ago

The ms08_067 exploiter is only valid for very old systems (Windows Server 2008 and earlier). It causes Infection Monkey to be flagged by Windows Defender. Since this vulnerability is so old, this exploiter is more trouble than it's worth.

mssalvatore commented 3 years ago

This branch removes the ms08_067 exploiter. Windows defender still detects the monkey agent as malicious. More investigation is needed as to the cause.