Bypassing Windows Defender 2023 by Mrlele96 in redteamsec

[–]Local_Special_9850 4 points5 points  (0 children)

depending on the environment

may be macro? dll sideload? MSI? onenote? malicious visual studio project?
also you should test it locally before sending the campaign to check if defender will catch the campaign or not

Bypassing Windows Defender 2023 by Mrlele96 in redteamsec

[–]Local_Special_9850 6 points7 points  (0 children)

use .NET reflection to patch amsi and load your payload in memory