mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-02-26 20:13:42 +01:00
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker |
||
---|---|---|
.. | ||
LOLUtilz | ||
OSBinaries | ||
OSLibraries | ||
OSScripts | ||
OtherMSBinaries |