Fucking defender, again. It seems to be their "cloud" protection shit which keeps detecting ViewSecurityDescriptor.exe. If I only knew why they were detecting it I might be able to change it to avoid it but of course they probably don't know if it's an ML signature.
-
-
Replying to @tiraniddo
Try: Naming it msiexec.exe Putting it in a folder, when launced set symlink on folder ADS. Make launcher that starts it suspended, then open the file with FILE_REQUIRE_OPLOCK and resume it Detect if running in sandbox by trying opening \\?\VMSMB then exit
2 replies 2 retweets 16 likes -
Replying to @jonasLyk @tiraniddo
Re. "Set a symlink on a folder ADS". Could you explain that a little more please?
1 reply 0 retweets 0 likes
Replying to @secure_sean @tiraniddo
look through my posting history- find the one where i disable defender
12:23 AM - 30 Oct 2020
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.