Obfuscation
Table of contents
- Antivirus bypass
- EDR bypass
- Tips and Tricks
Antivirus bypass
EDR bypass
Tips and Tricks
To check if a file has the Mark of the Web (MOTW).
Get-Content -Path $file -Stream Zone.Identifier
It exists 5 zones, in trust order:
- Local computer
- Local intranet
- Trusted sites
- Internet
- Restricted sites