<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why.]]></title><description><![CDATA[<p>Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. I fucking hate MS and Defender especially.</p>]]></description><link>https://board.circlewithadot.net/topic/9f573e1f-0a5c-432c-9c19-3d87aef2e8a5/fucks-sake-defender-is-now-signaturing-on-builds-of-my-v2-version-of-ntobjectmanager-god-knows-why.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 06:31:56 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/9f573e1f-0a5c-432c-9c19-3d87aef2e8a5.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 07 Apr 2026 20:25:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. on Mon, 20 Apr 2026 18:16:38 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@oct0xor">@<span>oct0xor</span></a></span> that's what caused v1 to be detected. In v2 I tried my best to refactor it until it stopped detecting and have never used it for a PoC since. Still, something must have decided to use it, or Defender is just detecting the use of a native API which happens to be used by malware somewhere.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tiraniddo/statuses/116438400917129515</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tiraniddo/statuses/116438400917129515</guid><dc:creator><![CDATA[tiraniddo@infosec.exchange]]></dc:creator><pubDate>Mon, 20 Apr 2026 18:16:38 GMT</pubDate></item><item><title><![CDATA[Reply to Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. on Mon, 20 Apr 2026 06:42:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/tiraniddo%40infosec.exchange">@<span>tiraniddo</span></a></span> I guess this is what happened:<br />1. You created NtApiDotNet and used it in dozens of PoCs submitted to MSRC<br />2. Defender team was tasked with creating detection for your PoCs, and the easiest way was to detect the use of NtApiDotNet, since it was mainly used for exploitation?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/oct0xor/statuses/116435670240587553</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/oct0xor/statuses/116435670240587553</guid><dc:creator><![CDATA[oct0xor@mastodon.social]]></dc:creator><pubDate>Mon, 20 Apr 2026 06:42:11 GMT</pubDate></item><item><title><![CDATA[Reply to Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. on Wed, 08 Apr 2026 07:21:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/tiraniddo%40infosec.exchange">@<span>tiraniddo</span></a></span> it is a big pain in my butt as well. I keep on getting sporadic reports around Ansible’s execution scripts being flagged by Defender/AMSI. I would like it a bit more if there was ways of trying to get the hash verified in some official process to lower the detection but alas it’s just a black box.</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/jborean/statuses/116367878796778347</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/jborean/statuses/116367878796778347</guid><dc:creator><![CDATA[jborean@fosstodon.org]]></dc:creator><pubDate>Wed, 08 Apr 2026 07:21:56 GMT</pubDate></item></channel></rss>