Article Excerpt
Abusing mhyprotect (not mhyprot2) to kill AVs / EDRs / XDRs / Protected Processes.
property | value |
tags | edr-evasion,github-repo,offensive-tradecraft,tradecraft-tool |
url | |
original_word_count | 24 |
Long Summary
Mhyprotect is a tool used to protect processes from being killed by malicious actors. However, it can be abused to kill antivirus (AVs), endpoint detection and response (EDRs), extended detection and response (XDRs), and protected processes. This article will discuss two resources that can be used to abuse mhyprotect for malicious purposes.
The first resource is Terminator, a tool developed by ZeroMemoryEx. It is a command line interface (CLI) that can be used to terminate processes and services. It can be used to terminate AVs, EDRs, XDRs, and protected processes. It also has the ability to bypass mhyprotect and terminate processes that are protected by it.
The second resource is evil-mhyprot-cli, a tool developed by kkent030315. It is a CLI that can be used to terminate processes and services. It can be used to terminate AVs, EDRs, XDRs, and protected processes. It also has the ability to bypass mhyprotect and terminate processes that are protected by it.
In conclusion, mhyprotect can be abused to kill AVs, EDRs, XDRs, and protected processes. There are two resources that can be used to abuse mhyprotect for malicious purposes: Terminator and evil-mhyprot-cli. Both of these tools have the ability to bypass mhyprotect and terminate processes that are protected by it. Therefore, it is important to be aware of the potential risks associated with mhyprotect and take steps to protect against malicious actors.
Short Summary
š zer0condition/mhydeath
šš½ Abusing mhyprotect (not mhyprot2) to kill AVs / EDRs / XDRs / Protected Processes. šš½ Mhyprotect is a tool used to protect processes from being killed by malicious actors. šš½ It can be abused to kill antivirus (AVs), endpoint detection and response (EDRs), extended detection and response (XDRs), and protected processes. šš½ The article discusses two resources that can be used to abuse mhyprotect for malicious purposes. šš½ Terminator is a tool developed by ZeroMemoryEx that can terminate processes and services. šš½ Terminator can terminate AVs, EDRs, XDRs, and protected processes. šš½ Terminator has the ability to bypass mhyprotect and terminate protected processes. šš½ evil-mhyprot-cli is a tool developed by kkent030315 that can terminate processes and services. šš½ evil-mhyprot-cli can terminate AVs, EDRs, XDRs, and protected processes. šš½ evil-mhyprot-cli has the ability to bypass mhyprotect and terminate protected processes. šš½ It is important to be aware of the risks associated with mhyprotect and protect against them.
š source link: https://github.com/zer0condition/mhydeath
š summarized content: https://hut.threathunterz.com/battlefield-intel/tradecraft-tools/zer0conditionmhydeath
#MhyprotectAbuse #TerminatorTool #EvilMhyprotCLI #ProcessTermination #MaliciousActors