mandiant / commando-vm

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
https://www.mandiant.com/resources/blog/commando-vm-windows-offensive-distribution
Apache License 2.0
6.88k stars 1.28k forks source link

BUG Windows 10 20H2, Windows Defender #184

Closed QHx5 closed 3 years ago

QHx5 commented 3 years ago

Describe the bug and expected behavior I know this Windows 10 Version (20H2) is not yet supported, I still write this bug report because you will probably run into this problem anyway, as soon as you extend the support.

Windows 10 will re-enable real-time protection after some time. This leads to an error during the installation process.

To Reproduce Simply start the installation and wait. Real-Time protection should activate after ~ one hour or after a reboot.

Version

Additional context This bug results likely because Microsoft did some changes to the Defender. It is not longer possible to permanently disable it using the registry or GPO. -> https://www.ghacks.net/2020/08/20/microsoft-makes-it-difficult-to-disable-windows-defender-on-windows-10/

gtjamesa commented 3 years ago

I managed to fix this by disabling Tamper Protection (as required) and then enabling GPOs to disable real-time protection and Windows Defender

day1player commented 3 years ago

fixed with june update #262