Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
hak5
GitHub Repository: hak5/usbrubberducky-payloads
Path: blob/master/payloads/library/general/Defeat_Defender/ReadMe.md
2968 views

Slightly modified version of the "Disable Windows Defender" by Zero_Sploit.

Updated by B33m0 to add exception of drive C: to Defender protection, and finally updated by UberGuidoZ to fix some UAC and newer Windows version issues.

Description: Opens security settings, disables Defender, then adds an exception of drive C for persistence.
NOTE: Requires local admin privileges

Target: Windows 10/11 (Powershell 2.0 or above)