Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Hello everyone, just a disclaimer before
the video. This video is presented
solely for educational and knowledge
sharing purposes. All demonstrations are
conducted in a legal isolated lab
environment on systems I own or have
explicit authorization to test. The
channel does not condone illegal
activities. Misuse of the tools or
techniques demonstrated may violate
applicable laws and organizational
policies, and viewers are responsible
for ensuring their own actions comply
with all legal and ethical requirements.
Hello everyone. It has been a long time
since the last upload. And here it is a
new video that demonstrates how a
publicly available tool published in
2024 can still be utilized today to
bypass the latest Windows Defender on a
Windows 11 machine to execute a
metasloit meta reverse shell. This is
the tool that we will be showing today.
A shell code loader or a shell code
packer known as super mega. There are a
few writeups and references that detail
about the tool. We won't be reading off
them to save time. So feel free to do so
to have a deeper understanding of the
tool.
We will need Visual Studio and Python
installed to run this. The actual
payload generator will be independent
and standalone. So the payload will work
without any dependencies on your victim
machine. If we were to try downloading
Super Mega directly, it will get picked
up by Windows Defender. This is due to
the default shell code templates that
come with the two source files. Let's
create a Windows Defender exclusion on
our downloads folder to get around it.
Of course, the actual Windows Defender
bypass will be executed from a folder
that is not part of Windows Defender
exclusion.
All right, the download works. Now,
let's extract the zip file.
If we were to look at the data binary
folder, this is where you can add your
own legitimate .exe executables and
shell codes.
We will need to use the Visual Studio
developer command prompt to launch this.
Else the build tools will not be part of
our path and the following error will be
encountered.
All right, it is [music] working. Now
let's browse to the super mega web
portal. It has a nice UI to generate our
payload. The web portal has some
descriptions of the usage of the tool.
Again, reading the references provided
in the GitHub page is strongly
recommended.
The injectable should be a legitimate
.exe executable that you want to back
door your shell code into. And the shell
code should be the payload that you want
to deliver such as a reverse shell. Now
let's hop over to our Kali machine and
generate a meta https reverse shell.
[music]
>> Now let's create a listener for the
reverse shell with MSF [music] console.
Let's transfer the shell code over to
our Windows machine so that Super Mega
can build our own custom .exe payload.
The Metrop shell code should show up now
in our Super Mega web portal.
By default, the shell code location is
set to R data. And in this case, this
will cause an error as the size is
insufficient to insert the shell code
into. Let's switch to text instead.
Let's leave the other options as default
and see how it goes.
Great. Super Mega was able to create the
payload successfully.
Now, let's transfer the compound .exe
payload to a folder that is not part of
Windows Defender exclusion, such as our
desktop folder instead.
Oh dear, it seems like Windows Defender
is able to pick up the .exe payload
immediately. Again, this tool was
published in 2024, so not really a
surprise that the default options get
picked up by Windows Defender.
Let's try again by changing the option
just a little bit. Let's set the decoy
option to win exec and recompile the
payload.
Now let's try transferring the compile
ESC payload again to our desktop folder.
Nice. There is no Windows Defender
detection anymore. This [music] is
looking good. Let's trigger a manual
scan on the ESE binary itself. Nice. No
threads were found. That [music] is
good.
Let's double click on the EXE payload to
execute it.
Awesome. We have a Metrop reverse shell
call back. Now we have successfully
bypassed the latest Windows Defender and
obtain a functional Metrop reverse
shell. This is pretty easy.
We can even do a quick scan on our
Windows 11 and see if it detects the
established Metrop reverse shell.
Nice. No detections and no threats were
found. Our Metaper reverse shell is also
still functional after the Windows
Defender scan.
All right, all this is it to today's
video. A quick and straightforward
demonstration with no BS. I hope you
have enjoyed the video and the hands-on
demonstration. Please help to like the
video and subscribe to the channel. It
will really help out the channel a lot.
Thanks all. I will see you all soon in
the next one. Bye.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.