optiv / ScareCrow

ScareCrow - Payload creation framework designed around EDR bypass.
2.71k stars 503 forks source link

Windows defender new sandbox #56

Closed ghost closed 2 years ago

ghost commented 2 years ago

Windows defender have a new sandbox now, not executing any script on the system

Tylous commented 2 years ago

I am sorry this statement does make much sense, can you elaborate on it.

NotSoEthical commented 2 years ago

Any useful tips for bypassing Windows Defender?

Tylous commented 2 years ago

Since Defender has no userland hooks I would use the -unmodified flag since unhook is pretty much useless