mirror of
https://github.com/LOLBAS-Project/LOLBAS
synced 2025-05-07 05:44:13 +02:00
DownloadFile option has been removed from current MpCmdRun.exe, but old binary remains on disk. Defender cmd line mitigation can be bypassed by simply renaming the binary in a folder controlled by the attacker