Windows Defender bypass
ID: 4e7a83e0-2ed9-50c9-b7bb-26ca7ec77a0f
STIX ID: report--4e7a83e0-2ed9-50c9-b7bb-26ca7ec77a0f
Feed Name: ThreatLocker Blog
Threat Score
This report demonstrates a proof-of-concept bypass of Windows Defender (CVE-2023-24934) in which an attacker hijacks the Defender update process to delete Mimikatz from the signature database, allowing its download and execution; affected Defender versions are prior to 4.18.2303.8, the exploit and PoC tool (wd-pretender.py) are publicly documented, and mitigations include patching Defender and using application allowlisting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
