Update README.md

This commit is contained in:
Matt Graeber
2022-12-13 14:43:44 -05:00
committed by GitHub
parent 06f9d6611f
commit c6e3dddcd0
+2 -2
View File
@@ -1,7 +1,7 @@
Use this PowerShell module to execute PowerShell code at the antimalware-light protection level. This code was highlighted in the [Living Off the Walled Garden: Abusing the Features of the Early Launch Antimalware Ecosystem
](https://cfp.recon.cx/2022/talk/MNTFHS/) REcon talk. This module needs to run elevated. The purpsoe of this module is to highlight how the antimalware-light protection anti-tampering feature is only as strong as the weakest vendor ELAM driver.
](https://cfp.recon.cx/2022/talk/MNTFHS/) REcon talk as well as [Black Hat USA 2022](https://www.youtube.com/watch?v=Upo5I_mK1V4). This module needs to run elevated. The purpose of this module is to highlight how the antimalware-light protection anti-tampering feature is only as strong as the weakest vendor's ELAM driver.
Thank you to the Microsoft Defender research team for working so diligently on a fix! When in doubt, if MSRC won't fix something because it's not a security boundary, the Defender team still likely cares very much!
Thank you to the Microsoft Defender research team for working with me on this issue! When in doubt, if MSRC won't fix something because it's not a security boundary, the Defender team still likely cares very much!
Load the module: