How to Bypass Anti-Virus to Run Mimikatz
ID: d282eb5f-e368-574a-a29f-a2dea010dda2
STIX ID: report--d282eb5f-e368-574a-a29f-a2dea010dda2
Feed Name: Black Hills Infosec Blog
Threat Score
This report demonstrates how simple text substitutions and comment removal in the PowerShell Invoke-Mimikatz script can bypass multiple AV engines, reducing detections to zero in the author's tests and enabling successful dumping of cleartext credentials from memory; it highlights the limitations of signature-based AV and the risk of relying solely on antivirus for protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
