Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PowerLine and defender in Win 10 #12

Open
slavadba opened this issue Jun 7, 2020 · 0 comments
Open

PowerLine and defender in Win 10 #12

slavadba opened this issue Jun 7, 2020 · 0 comments

Comments

@slavadba
Copy link

slavadba commented Jun 7, 2020

Hi,

I tested several scripts, the results are as follows:

1 ) mimikatz - access denied. If I turn off WD - its not worked but with diffrent errors, so - its another story, but defender some catches it anyway.

2 ) empire http listener and https://raw.githubusercontent.com/peewpw/Invoke-WCMDump/master/Invoke-WCMDump.ps1

here very strange situation: its not blocked directly (no notifications from WD and so on) but its not worked. Those - if I turn off WD - its fine, all goes well.
But then its running - no way: empire and WCMDump just "dies" without any messages:

C:\DISTR\POWERLINE\PowerLine-master\PowerLine-master\PowerLine>PowerLine.exe Invoke-WCMDump "Invoke-WCMDump"

Command Invoked: Invoke-WCMDump

C:\DISTR\POWERLINE\PowerLine-master\PowerLine-master\PowerLine>

So, something has changed in WD and its rules - maybe you have some clues how solve it?
Especially interested in the option with Empire

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant