⤷ Title: Packing Heat: How to Keep Windows Defender Off Your Back (Maybe)
════════════════════════
𐀪 Author: SilentInject
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 14:34:48 GMT
════════════════════════
⌗ Tags: #executable_packing #reverse_engineering #windows_defender #malware_analysis #cybersecurity
════════════════════════
𐀪 Author: SilentInject
════════════════════════
ⴵ Time: Thu, 31 Jul 2025 14:34:48 GMT
════════════════════════
⌗ Tags: #executable_packing #reverse_engineering #windows_defender #malware_analysis #cybersecurity
Medium
Packing Heat: How to Keep Windows Defender Off Your Back (Maybe)
Okay, let’s talk about staying under the radar of Windows Defender. We’re not talking about anything malicious here, just exploring the…
⤷ Title: Sophisticated Kimsuky Campaign: New Malware Bypasses Windows Defender
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:25:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Kimsuky #LNK #malware #Social Engineering #South Korea #Windows Defender
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 00:25:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Kimsuky #LNK #malware #Social Engineering #South Korea #Windows Defender
Penetration Testing Tools
Sophisticated Kimsuky Campaign: New Malware Bypasses Windows Defender
The Kimsuky group is targeting South Korean agencies with new malware that uses social engineering and code obfuscation to bypass Windows Defender and steal data.
⤷ Title: Akira Ransomware Uses Intel Driver to Bypass Windows Defender
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 08:57:46 +0000
════════════════════════
⌗ Tags: #Malware #Akira #BYOVD #cybersecurity #Intel #ransomware #SonicWall #Windows Defender
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 08 Aug 2025 08:57:46 +0000
════════════════════════
⌗ Tags: #Malware #Akira #BYOVD #cybersecurity #Intel #ransomware #SonicWall #Windows Defender
Penetration Testing Tools
Akira Ransomware Uses Intel Driver to Bypass Windows Defender
The Akira ransomware gang is now using a legitimate Intel driver in a "Bring Your Own Vulnerable Driver" attack to disable Windows Defender and encrypt systems.
⤷ Title: New NightshadeC2 Botnet Exploits UAC Prompt Bombing to Evade Windows Defender
════════════════════════
𐀪 Author: Jasmitharouthu
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 11:35:55 GMT
════════════════════════
⌗ Tags: #windows_defender #malware_attack #coe_security #botnet_threat #cybersecurity
════════════════════════
𐀪 Author: Jasmitharouthu
════════════════════════
ⴵ Time: Fri, 05 Sep 2025 11:35:55 GMT
════════════════════════
⌗ Tags: #windows_defender #malware_attack #coe_security #botnet_threat #cybersecurity
Medium
New NightshadeC2 Botnet Exploits UAC Prompt Bombing to Evade Windows Defender
Cybercriminals are deploying a new and dangerous botnet, known as NightshadeC2, which leverages an advanced technique called UAC Prompt…
⤷ Title: NightshadeC2: A New Botnet Is Using “UAC Prompt Bombing” to Bypass Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ClickFix #cybersecurity #malware #NightshadeC2 #Trojanized Software #UAC Prompt Bombing #Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 08 Sep 2025 00:16:12 +0000
════════════════════════
⌗ Tags: #Malware #botnet #ClickFix #cybersecurity #malware #NightshadeC2 #Trojanized Software #UAC Prompt Bombing #Windows Defender
Daily CyberSecurity
NightshadeC2: A New Botnet Is Using "UAC Prompt Bombing" to Bypass Windows Defender
A new botnet, NightshadeC2, is using a technique called "UAC Prompt Bombing" to bypass sandboxes and Windows Defender by relentlessly looping UAC prompts.
⤷ Title: Hackers Exploit Windows Defender Policies to Disable EDR Agents
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Mon, 15 Sep 2025 02:21:23 GMT
════════════════════════
⌗ Tags: #windows_defender #security #wdac #hacking
════════════════════════
𐀪 Author: SafetyDetectives Research Team
════════════════════════
ⴵ Time: Mon, 15 Sep 2025 02:21:23 GMT
════════════════════════
⌗ Tags: #windows_defender #security #wdac #hacking
Medium
Hackers Exploit Windows Defender Policies to Disable EDR Agents
Attackers are exploiting Windows Defender Application Control (WDAC) policies to disable Endpoint Detection and Response (EDR) agents…
⤷ Title: Your Digital Gatekeeper: A Practical Guide to Understanding and Using Firewalls
════════════════════════
𐀪 Author: Sumit Sah
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 15:48:07 GMT
════════════════════════
⌗ Tags: #firewall #linux #cybersecurity #windows_defender #network_security
════════════════════════
𐀪 Author: Sumit Sah
════════════════════════
ⴵ Time: Wed, 15 Oct 2025 15:48:07 GMT
════════════════════════
⌗ Tags: #firewall #linux #cybersecurity #windows_defender #network_security
Medium
Your Digital Gatekeeper: A Practical Guide to Understanding and Using Firewalls
What Is the Purpose of a Firewall
⤷ Title: Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
Daily CyberSecurity
Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
ENKI exposed a Kimsuky APT campaign using a dual PE/PowerShell payload that switches based on Windows Defender status to deploy KimJongRAT. The malware steals Chrome AppBound keys via GitHub Releases C2.
⤷ Title: YOUR PC’S DIGITAL SHIELDS
════════════════════════
𐀪 Author: Keyur
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 10:34:02 GMT
════════════════════════
⌗ Tags: #windows_defender #cybersecurity #windows_firewall
════════════════════════
𐀪 Author: Keyur
════════════════════════
ⴵ Time: Fri, 28 Nov 2025 10:34:02 GMT
════════════════════════
⌗ Tags: #windows_defender #cybersecurity #windows_firewall
Medium
YOUR PC’S DIGITAL SHIELDS
Your computer is equipped with the inbuilt security features, which help to mitigate the potential vulnerabilities to exploit the system or…
⤷ Title: Blocking EDRs traffic: C-Based Tools That Block EDR Network Traffic via Windows Firewall and WFP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:07:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR evasion #endpoint security #firewall rules #red team tools #WFP filters #Windows Defender Firewall #Windows Filtering Platform #Windows internals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 08:07:20 +0000
════════════════════════
⌗ Tags: #Open Source Tool #EDR evasion #endpoint security #firewall rules #red team tools #WFP filters #Windows Defender Firewall #Windows Filtering Platform #Windows internals
Penetration Testing Tools
Blocking EDRs traffic: C-Based Tools That Block EDR Network Traffic via Windows Firewall and WFP
New C-based tools demonstrate how EDR network traffic can be blocked using Windows Defender Firewall and WFP without disabling security software.
⤷ Title: EDRStartupHinder: New Tool Abuses Windows Bindlinks to Hinder EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 04:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bindlink #Boot Security #Cybersecurity 2026 #DLL Redirection #EDR Bypass #EDRStartupHinder #EDRStartupHinder bypass #System32 #Windows 11 25H2 #Windows Defender #Zero Salarium
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 14 Jan 2026 04:04:00 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bindlink #Boot Security #Cybersecurity 2026 #DLL Redirection #EDR Bypass #EDRStartupHinder #EDRStartupHinder bypass #System32 #Windows 11 25H2 #Windows Defender #Zero Salarium
Penetration Testing Tools
EDRStartupHinder: New Tool Abuses Windows Bindlinks to Hinder EDR
EDRStartupHinder exploits the Windows Bindlink API to redirect System32 DLLs at boot, causing EDR and antivirus tools to crash before they can start.
⤷ Title: Bypassing AMSI
════════════════════════
𐀪 Author: z3l3v
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 20:40:08 GMT
════════════════════════
⌗ Tags: #amsi_bypas #windows_defender #ethical_hacking #red_team #windows
════════════════════════
𐀪 Author: z3l3v
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 20:40:08 GMT
════════════════════════
⌗ Tags: #amsi_bypas #windows_defender #ethical_hacking #red_team #windows
Medium
Bypassing AMSI
I recently began reviewing some material to reinforce my understanding in some areas. During a session where I was practicing File Transfer…
⤷ Title: The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 02:03:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #infosec #Malware Analysis #Memory_Resident Payload #reflective loading #social engineering #Telegram malware #threat intelligence #Typosquatting #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 02:03:28 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #infosec #Malware Analysis #Memory_Resident Payload #reflective loading #social engineering #Telegram malware #threat intelligence #Typosquatting #Windows Defender Bypass
Daily CyberSecurity
The Typosquatting Trap: Fake Telegram Portal Delivers Stealthy Memory-Resident Malware
Researchers uncover a fake Telegram site distributing stealthy, memory-resident malware that bypasses Windows Defender. Always verify your download URLs.