mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-04-16 03:44:04 +02:00
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker