logo

How to Bypass Anti-Virus to Run Mimikatz

ID: d282eb5f-e368-574a-a29f-a2dea010dda2

STIX ID: report--d282eb5f-e368-574a-a29f-a2dea010dda2

Feed Name: Black Hills Infosec Blog

Threat Score
70/100

Date Published: 2017-01-05

Date Updated: 2026-04-27

Author: BHIS

...
...

This report demonstrates how simple text substitutions and comment removal in the PowerShell Invoke-Mimikatz script can bypass multiple AV engines, reducing detections to zero in the author's tests and enabling successful dumping of cleartext credentials from memory; it highlights the limitations of signature-based AV and the risk of relying solely on antivirus for protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.