Skip to content

5l1v3r1/WinDefendInjectPoC

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

WinDefendInjectPoC

This is the PoC for https://halove23.blogspot.com/2021/08/executing-code-in-context-of-trusted.html

How to use ?

Place your desired dll to be load next to the PoC with the name "MpSvc.dll", and note that the dll must contain a service CTRL handler if you'd to keep windows defender alive, because services.exe will terminate the process if it didn't gave a responce within 30 seconds. The PoC must be executed as "NT AUTHORITY\SYSTEM" in order to function.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • C++ 100.0%