/loader

shellcode分离加载器

Primary LanguageC++

loader

shellcode分离加载器

How to test by yourself

  • Create a new directory, copy C:\Program Files\Windows Defender\NisSrv.exe in this new directory
  • Copy mpclient.dll and mimikatz.bin to the same directory.
  • Usage: NisSrv.exe mimikatz.bin

引用

https://github.com/Sh0ckFR/Lockbit3.0-MpClient-Defender-PoC