PowerShellRunner icon indicating copy to clipboard operation
PowerShellRunner copied to clipboard

PowerShell runner for executing malicious payloads in order to bypass Windows Defender.

PowerShellRunner

PowerShell script that utilizes WinAPI for bypassing Windows Defender implementation as of August 2, 2021. Using a msfvenom windows/x64/meterpreter/reverse_https ps1 shellcode will result in successful shell access. Shellcode should replace the placeholder in the script.