How To ByPass Windows Defender and Elastic Security With PowerCat! WORKS!

แชร์
ฝัง
  • เผยแพร่เมื่อ 27 ก.ย. 2024
  • Is it possible to bypass windows defender and elastic security at the same time with a powercat reverse shell?
    The best purple teaming series on youtube with real hands on learning for everyone!
    For educational purposes only!
    Subscribe and like for more!
    Connect with me on linkedin: / howard-mukanda-24503144
    Follow me on twitter: / lahilabs
    Powercat is "..Powershell Netcat which is a new version of netcat in the form of the powershell script" : www.hackingart... and can be found on github: github.com/bes... Connect and Direct Message me on Linkedin: / howard-mukanda-24503144

ความคิดเห็น • 18

  • @michaelojo6839
    @michaelojo6839 ปีที่แล้ว +2

    Thanks for this walk-through. The hair cut looks good on you.

  • @abdullahasif5992
    @abdullahasif5992 ปีที่แล้ว

    really love this type of videos, Can you do detection videos of lolbins pls

  • @andanimasikhwa6852
    @andanimasikhwa6852 11 หลายเดือนก่อน

    Loved It!

  • @zk321
    @zk321 7 หลายเดือนก่อน

    can the attacker be a machine on the cloud

  • @giomke
    @giomke ปีที่แล้ว +1

    Can you bypass with meterpreter payload ?
    Give us more real life practical examples

    • @ITSecurityLabs
      @ITSecurityLabs  ปีที่แล้ว +2

      I could, bypass it, meaning the payload stayed on disk but behavioral detection is a beast! I am taking more courses to work on more custom implants

    • @thebest_progamer
      @thebest_progamer 4 หลายเดือนก่อน

      @@ITSecurityLabs defender wasn't complaining because there is a powershell window opened

  • @xxfdttr3307
    @xxfdttr3307 9 หลายเดือนก่อน

    Is it possible to use the msfconsole to setup the listener for this power cat exploit and could you please make a video?

  • @kuyadio436
    @kuyadio436 8 หลายเดือนก่อน +1

    What cve is this?

  • @przemysawpacyna1089
    @przemysawpacyna1089 11 หลายเดือนก่อน

    It will not be detected and blocked by defender immediately once the encoded file will be decoded to execute it? How's that work then?
    In domain enviroments it's anyway all more restricted

    • @ITSecurityLabs
      @ITSecurityLabs  11 หลายเดือนก่อน

      I was able to run it for a while. Yes in domain environments you might have things like applocker, constrained powershell etc

  • @RaGhav363
    @RaGhav363 11 หลายเดือนก่อน

    Please just don't close any function of Microsoft defender and than try to penetrate it you can also add some AVs IDS firewall on top of it

    • @arjunraghunadhan3611
      @arjunraghunadhan3611 8 หลายเดือนก่อน

      Are you dumb
      You are telling to enable sample submission to make fud malware into known one
      Seriously

  • @firosiam7786
    @firosiam7786 ปีที่แล้ว +1

    Love this new series mate

    • @ITSecurityLabs
      @ITSecurityLabs  ปีที่แล้ว

      This is the fun stuff 👍

    • @firosiam7786
      @firosiam7786 ปีที่แล้ว

      @@ITSecurityLabs looking forward for more fun with av