Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why.

Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why.

Scheduled Pinned Locked Moved Uncategorized
4 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • tiraniddo@infosec.exchangeT This user is from outside of this forum
    tiraniddo@infosec.exchangeT This user is from outside of this forum
    tiraniddo@infosec.exchange
    wrote last edited by
    #1

    Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. I fucking hate MS and Defender especially.

    jborean@fosstodon.orgJ oct0xor@mastodon.socialO 2 Replies Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • tiraniddo@infosec.exchangeT tiraniddo@infosec.exchange

      Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. I fucking hate MS and Defender especially.

      jborean@fosstodon.orgJ This user is from outside of this forum
      jborean@fosstodon.orgJ This user is from outside of this forum
      jborean@fosstodon.org
      wrote last edited by
      #2

      @tiraniddo it is a big pain in my butt as well. I keep on getting sporadic reports around Ansible’s execution scripts being flagged by Defender/AMSI. I would like it a bit more if there was ways of trying to get the hash verified in some official process to lower the detection but alas it’s just a black box.

      1 Reply Last reply
      0
      • tiraniddo@infosec.exchangeT tiraniddo@infosec.exchange

        Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why. I fucking hate MS and Defender especially.

        oct0xor@mastodon.socialO This user is from outside of this forum
        oct0xor@mastodon.socialO This user is from outside of this forum
        oct0xor@mastodon.social
        wrote last edited by
        #3

        @tiraniddo I guess this is what happened:
        1. You created NtApiDotNet and used it in dozens of PoCs submitted to MSRC
        2. Defender team was tasked with creating detection for your PoCs, and the easiest way was to detect the use of NtApiDotNet, since it was mainly used for exploitation?

        tiraniddo@infosec.exchangeT 1 Reply Last reply
        0
        • oct0xor@mastodon.socialO oct0xor@mastodon.social

          @tiraniddo I guess this is what happened:
          1. You created NtApiDotNet and used it in dozens of PoCs submitted to MSRC
          2. Defender team was tasked with creating detection for your PoCs, and the easiest way was to detect the use of NtApiDotNet, since it was mainly used for exploitation?

          tiraniddo@infosec.exchangeT This user is from outside of this forum
          tiraniddo@infosec.exchangeT This user is from outside of this forum
          tiraniddo@infosec.exchange
          wrote last edited by
          #4

          @oct0xor that's what caused v1 to be detected. In v2 I tried my best to refactor it until it stopped detecting and have never used it for a PoC since. Still, something must have decided to use it, or Defender is just detecting the use of a native API which happens to be used by malware somewhere.

          1 Reply Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups