@tiraniddo I guess this is what happened:
1. You created NtApiDotNet and used it in dozens of PoCs submitted to MSRC
2. Defender team was tasked with creating detection for your PoCs, and the easiest way was to detect the use of NtApiDotNet, since it was mainly used for exploitation?
oct0xor@mastodon.social
@oct0xor@mastodon.social
Posts
-
Fucks sake, Defender is now signaturing on builds of my v2 version of NtObjectManager, god knows why.