TGViewer
Security Analysis Security Analysis @securation · 12.6K subscribers
Post #1604 6.66K
⭕️ اسکریپتی توسعه داده شده است که از ابزارهای توسعه داده قبلی مانند EDRSilencer و FireBlock بهره برده است. هدف اصلی این اسکریپت، شناسایی فایل های اجرایی مختلف است که با استفاده از پلتفرم فیلترینگ ویندوز (WFP) غیر فعال شده اند. برای دستیابی به این هدف، از ماژول NtObjectManager در اسکریپت استفاده شده است.

Detection approach

There is no native way to list and interact with WFP. To do that we need to use the NtObjectManager module.

With the help of NtObjectManager we will be able to list all filters and the approach will be:

Create a list with the executables you want to check
Listed filters that block connections
Filter that list by the executables provided


#RedTeam #Evasion
@securation
GitHub GitHub - amjcyber/EDRNoiseMaker: Detect WFP filters blocking EDR communications Detect WFP filters blocking EDR communications. Contribute to amjcyber/EDRNoiseMaker development by creating an account on GitHub.
  • 👍 7
  • 👎 1
More from @securation
  1. Oct 9, 2026⭕️تحلیل آسیب پذیری تلگرام تلگرام scheme مربوط به tg:// رو در سیستم‌عامل register میکنه؛ کل…
  2. Oct 9, 2026‌ حماقت بزرگی است که آدمی به منظور برنده شدن در بیرون، در درون ببازد، یعنی برای شوکت، مقام…
  3. Oct 8, 2026میدونستید اگر باگ بانتی ایرانی کار کنید هر مبلغی که دریافت می‌کنید باید یکسال یا دوسال یا…
  4. Oct 5, 2026⭕️ خطرات امنیتی پنهان در فناوری Direct-to-Cell (D2C) فناوری Direct-to-Cell این امکان را فر…
  5. Oct 5, 2026⭕️ارتباطات ماهواره‌ای استارلینک و فناوری‌های سلولی منابع ارائه شده به بررسی جامع فناوری ار…
  6. Sep 28, 2026ترس توی ذهن آدم با فکر کردن بزرگتر میشه. اما وقتی دست به اقدام میزنی کوچیکتر میشه. @secura…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →