ZeroMemoryEx / Terminator

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

A little suggestion!

ttsite opened this issue · comments

commented

Try several methods to start the machine, but it has not been possible to achieve this! As long as the system is right-click to run in management mode, it is possible. Below are several methods I have tried. I hope to add at least one. Thank you!

1 Manually adding scheduled tasks, whether initiated in system mode or by an administrator, cannot be started.
2 Adding services through third-party software also prevents startup.
3 Manually add services through the cmd command driver. However, the main program cannot be started even after adding the boot up command.

Summarized and tried various methods. The main program exe can only run normally by right-clicking the administrator within the system. Other methods seem to be unable to open the main program exe

commented

Hello @ttsite , I didn't understand you correctly, but the program runs correctly on the latest patched versions of Windows. Just run it as an administrator and let it do the work , If you have any questions , please don't hesitate to open a ticket , enjoy.

commented

It seems that you are requesting a persistence technique to be added, correct?

commented

It seems that you are requesting a persistence technique to be added, correct?

Yes, I do. Alternatively, it can be started through third-party services or programs. The current program can only run in administrator mode within the system and cannot be successfully run in any other way. It can only be manually clicked

commented

It seems that you are requesting a third-party program to drop this program and run, This can be easily done, However, the purpose of this project is not to make the program evasive against static/dynamic analysis .