Skip to content

lab52io/StopDefender

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

23 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

StopDefender

Stop Windows Defender programmatically creating a new token using TrustedInstaller and Windefend service accounts.

One button stop action, no need for supply commandline options nor pid. Usefull for integration with Post Explotation frameworks.

Blogpost

https://www.securityartwork.es/2021/09/27/trustedinstaller-parando-windows-defender/

Presentations

Check Presentations folder

  • [Rootedcon Valencia 2022] Kill -9 Windows Defender

Credits

About

Stop Windows Defender programmatically

Resources

License

Stars

Watchers

Forks

Packages

 
 
 

Contributors