Volver al ranking

swagkarna/Defeat-Defender-V1.2.0

Batchfile

Powerful batch script to dismantle complete windows defender protection and even bypass tamper protection ..Disable Windows-Defender Permanently....Hack windows. POC

bypassdefenderantivirusfudmalwarepayloadmalware-dropperbypass-antivirusundetectableav-evasiondropperhacking
Crecimiento de estrellas
Estrellas
1.5k
Forks
312
Crecimiento semanal
Issues
0
5001k1.5k
dic 2020jun 2022ene 2024ago 2025
README

Defeat-Defender-1.2


  • If you like the tool and for my personal motivation so as to develop other tools please leave a +1 star

Powerfull Batch File To Disable Windows Defender,Firewall,Smartscreen And Execute the payload

Usage :

  • Run run.bat and enter the direct link of your malware
  • Run the script "Defeat-Defender.bat" . It will ask for Admin Permission.If permission Granted The script will work Silently and dismantle all protection...

After it got admin permission it will disable defender

  • PUAProtection
  • Automatic Sample Submission
  • Windows FireWall
  • Windows Smart Screen(Permanently)
  • Disable Quickscan
  • Add exe file to exclusions in defender settings
  • Disable Defender Notification (Added Recently)
  • Disable UAC(Reboot Required)
  • Disable Ransomware Protection
  • Disable TaskManager
  • Disable registry etc..

Proof-Of-Concept

https://user-images.githubusercontent.com/46685308/120778529-0bb82e80-c544-11eb-9a54-d7f5d30fddd0.mp4


Bypasssing Windows-Defender Techniques :

Recently Windows Introduced new Feature called "Tamper Protection".Which Prevents the disable of real-time protection and modifying defender registry keys using powershell or cmd...If you need to disable real-time protection you need to do manually....But We will disable Real Time Protection using NSudo without trigerring Windows Defender


Running Defeat-Defender Script

Tested on Windows 11 Pro


After Reboot


Warning

This Script will completely Disable Windefend Services . And also it is very difficult to revert the changes..Think twice before you run the script


Behind The Scenes :

When Batch file is executed it ask for admin permissions.After getting admin privileage it starts to disable windows defender real time protectin , firewall , smartscreen and starts downloading our backdoor from server and it will placed in startup folder.The backdoor will be executed after it has downloaded from server..And will be started whenever system starts..


Check out this article :

https://secnhack.in/create-fud-fully-undetectable-payload-for-windows-10/


Note :

If you want to enable Defender Smart Screen.Use Smart Screen.bat file..


Discalimer :

Use this only for educational Purpose...Love you Guys Bye.....


Contact :


Inspired From TechChip


Special thanks to Jeffrey-d-howard(Senior Vulnerability Management Lead) For Posting Defeat-Defender on his linked page


❤️Supporters❤️

Stargazers repo roster for @swagkarna/Defeat-Defender-V1.2.0

Forkers repo roster for @swagkarna/Defeat-Defender-V1.2.0


Repositorios relacionados
swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

PythonPyPIMIT Licensepentestpayload
swisskyrepo.github.io/PayloadsAllTheThings/
79.3k17.2k
Max-Eee/NeoPass

Your Essential Exam Companion for the Iamneo Portal & NPTEL Exams Disguised as NeoExamShield bypass

JavaScriptnpmaichrome-extension
neopass.tech
24.8k94
MatrixTM/MHDDoS

Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods

PythonPyPIMIT Licenseddosddos-attacks
16.4k3.6k
GTFOBins/GTFOBins.github.io

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

YAMLGNU General Public License v3.0post-exploitationlinux
gtfobins.org
13.5k1.6k
screetsec/TheFatRat

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .

CGNU General Public License v3.0thefatratbypass
11.4k2.5k
everywall/ladder

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

GoGo ModulesGNU General Public License v3.0bypasspaywall
8.7k508
Mr-xn/Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

HTMLApache License 2.0penetration-testingpoc
mrxn.net
7.4k2k
daffainfo/AllAboutBugBounty

All about bug bounty (bypasses, payloads, and etc)

bugbountybugbountytips
6.8k1.3k
k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

PowerShellMIT Licenseexploit0day
k8gege.org
6.2k2.1k
esrrhs/pingtunnel

Pingtunnel is a tool that send TCP/UDP traffic over ICMP

GoGo ModulesMIT Licensetunnelping
3.7k599
matro7sh/BypassAV

This map lists the essential techniques to bypass anti-virus and EDR

avbypass
matro7sh.github.io/BypassAV/
3.4k374
tegal1337/CiLocks

Crack Interface lockscreen, Metasploit and More Android/IOS Hacking

HTMLGNU General Public License v3.0bypassbruteandroid
3k539