Ingress vulnerable Windows Defender binary

/static/assets/windows-logo.svg
Ingress a vulnerable version of Windows Defender Antimalware Service Executable (4.5.218.0) that can side-load a properly formatted Dynamic-link Library (DLL) that exports the function ServiceCrtMain.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
Kaseya VSA Attack

2021-08-16

/static/assets/windows-logo.svg
Side-load an agent using components of the REvil ransomware attack kill chain.