mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-06-21 02:55:02 +02:00
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker