- Apr 13, 2013
- 3,224
- Content source
- https://www.youtube.com/watch?v=wPf1GRbGPt0
So Defender is finally blocking Magniber by behaviour?
At least this is good news.
I‘m actually also excited about SAC.
Of course nothing new to the security world, but being a default part of Windows (even in the „free“ Home version - upgraded from 10 -> 11, activated itself silently) sounds great to me if it works out and does not generate too many FP.
Mine is currently evaluating, since i fresh-installed Win11 22H2 yesterday.
I did not test it yet, too, after setting everything up yesterday and today, I noticed the feature scrolling trough Updates and later Defense settings.And what do you think of SAC if you have tested it?
I installed W11 22h2 yesterday on VM in fresh install, but didn't have time to test SAC against scripts and other malwares yet
Well, no, it failed quite well. And as to SAC it is extremely limited as how many ONLY have fresh installs without anything else being on the system? And even then if disabled only another fresh install will enable it.So Defender is finally blocking Magniber by behaviour?
She often uses some French, or Latin just to throw everybody off. My high school Latin is rusty!(I also liked the end when you wrote in French )
Almost expected, as blocking happened instant in your video.Well, no, it failed quite well. And as to SAC it is extremely limited as how many ONLY have fresh installs without anything else being on the system? And even then if disabled only another fresh install will enable it.
Further SAC seems to obsess over only allowing legitimately signed applications while rejecting those that are not. This would be an issue for many common programs (like Seamonkey browser) which would not be allowed. This kind of protection routine would leave the final decision in the hands of the user as one would not know what is real and what isn't, never a good thing.
I didn't notice any blocks or alerts upon the script file being launched, only the installer (msi) file.Almost expected, as blocking happened instant in your video.
+1It would be interesting if this malicious script is blocked by Defender's ASR rules + highest Cloud Protection Level.
What follows from the video?
It would be interesting if this malicious script is blocked by Defender's ASR rules + highest Cloud Protection Level. If not, then it would mean that Microsoft still does not treat Magniber as really dangerous in the wild.
- Microsoft did not improve the Controlled Folder Access to block the technique used by Magniber.
- Scripts are usually more dangerous than other popular file types.
Cool! In Layman's terms, how did you do that?I just tested
I rebuilt Magniber in .JS by killing the Microsoft Defender detection.
Cool! In Layman's terms, how did you do that?
I rebuilt Magniber in .JS by killing the Microsoft Defender detection.
ASR / High rules are still on... no detection!
View attachment 269529
You do not do anything wrong - @cruelsister is usually cruel, but can be sometimes a sister, too.+1
I don't know what I do wrong to always get ignored by her if I ask something. Maybe you get a reply at least.
Could you look in the ConfigureDefender at the <Defender Security Log> to identify the detection details?