Skip to content

AV detection avoidance #929

@VakarisZ

Description

@VakarisZ

Describe the bug

Windows defender blocks Infection Monkey:
image

To Reproduce

Steps to reproduce the behavior:

  1. Install 1.9
  2. During installation process, defender removes windows-monkey32.exe and ms08_067.py exploiter.

Expected behavior

We should improve our payload obfuscation mechanism, because it's not the first time it happened: #801
Possible solutions:
Change obfuscation techniques and apply to all payloads.
Do not include exploiter PY files into the installer (they are unused anyway)
Rename files not to include the name of the actual vuln?

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions