Defeating Windows Defender

Defeating Windows Defender

54mAdvanced2024-04-24

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

The course explains the approach to malware detection in the Windows environment, and the way in which the Windows Defender anti-malware software uses the anti-malware service interface (AMSI) to stop penetration testing tools being used on Windows Workstations and Servers. Instructor Malcolm Shore covers system administrator methods of switching off or removing Defender, the basic approaches used in penetration testing to avoid detection such as obfuscation and living off the land, and the various technical approaches such as memory patching and DLL hooking. At the end of the course, you should have a good working knowledge of how to defeat Windows Defender anti-malware controls.

Skills covered

Microsoft DefenderPenetration TestingCybersecurityMicrosoftOne-Off

Concepts

Introduction

  • Understanding how hackers get past Windows Defender
  • What you should know
  • Disclaimer

Manipulating Defender

  • Introduction to Defender and AMSI
  • Defender real-time protection
  • Defender Advanced Threat Protection
  • Disabling Defender on Windows 10
  • Disabling Defender in Windows 11
  • Disabling Defender in Windows Servers

Obfuscation

  • Obfuscating your payloads
  • Creating an obfuscated msfvenom payload
  • Using phantom evasion
  • Using a simple shell

Bypassing AMSI

  • Digging into AMSI
  • Disrupting the AmsiOpenSession function
  • Disrupting the AmsiScanBuffer function
  • Using obfuscation for an AMSI bypass
  • Using Powercat after AMSI bypass

Conclusion

  • What's next
40,000 Toman