{"id":1345,"date":"2023-04-11T14:13:05","date_gmt":"2023-04-11T06:13:05","guid":{"rendered":"https:\/\/blog.langsasec.cn\/?p=1345"},"modified":"2023-04-11T14:13:16","modified_gmt":"2023-04-11T06:13:16","slug":"windows-defendernonono","status":"publish","type":"post","link":"https:\/\/blog.langsasec.cn\/index.php\/2023\/04\/11\/windows-defendernonono\/","title":{"rendered":"Windows Defender\uff1f\u522b\u7ed5\u4e86\uff01"},"content":{"rendered":"<p><strong>\u6211\u4eec\u5e73\u5e38\u62ff\u5230webshell\u60f3\u8981c2\u4e0a\u7ebf\uff1f\u6076\u5fc3\u7684Windows Defender\u600e\u4e48\u529e\uff0c\u6d6a\u98d2\u82b110\u5206\u949f\u7ed9\u4f60\u5199\u4e00\u7bc7\u6587\u7ae0\u3002<\/strong><\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e6%96%b9%e6%b3%95%e4%b8%80\"><\/span><strong>\u65b9\u6cd5\u4e00<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<pre class=\"prettyprint linenums\" ><code>powershell -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath &quot;C:\\JAVA&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/img2023.cnblogs.com\/blog\/2411575\/202304\/2411575-20230411141218838-440339771.png\" alt=\"\u56fe\u7247\" title=\"Windows Defender\uff1f\u522b\u7ed5\u4e86\uff01\u63d2\u56fe\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/img2023.cnblogs.com\/blog\/2411575\/202304\/2411575-20230411141214518-1229633182.png\" alt=\"\u56fe\u7247\" title=\"Windows Defender\uff1f\u522b\u7ed5\u4e86\uff01\u63d2\u56fe1\" \/><\/p>\n<p><strong>\u89e3\u91ca\u4e00\u4e0b\uff1a<\/strong><\/p>\n<p>\u8fd9\u662f\u4e00\u6761 PowerShell \u547d\u4ee4\uff0c\u7528\u4e8e\u5c06\u8def\u5f84 &quot;C:\\JAVA&quot; \u6dfb\u52a0\u5230 Windows Defender \u7684\u626b\u63cf\u6392\u9664\u5217\u8868\u4e2d\u3002<\/p>\n<p>\u5177\u4f53\u6765\u8bf4\uff0c<code>PowerShell<\/code> \u662f Windows \u5e73\u53f0\u4e0a\u7684\u4e00\u79cd\u811a\u672c\u8bed\u8a00\u548c\u547d\u4ee4\u884c\u5de5\u5177\uff0c\u53ef\u4ee5\u7528\u5b83\u6765\u7ba1\u7406\u548c\u914d\u7f6e\u8ba1\u7b97\u673a\u7cfb\u7edf\u4ee5\u53ca\u81ea\u52a8\u5316\u7ba1\u7406\u4efb\u52a1\u3002<code>-ExecutionPolicy Bypass<\/code> \u53c2\u6570\u7528\u4e8e\u8df3\u8fc7\u6267\u884c\u7b56\u7565\uff0c\u4ee5\u4fbf\u5728\u7cfb\u7edf\u4e0a\u6267\u884c\u6b64\u547d\u4ee4\u3002<code>Add-MpPreference<\/code> cmdlet \u7528\u4e8e\u5411 Windows Defender \u6dfb\u52a0\u9996\u9009\u9879\uff0c\u5e76\u4e14<code>-ExclusionPath<\/code> \u53c2\u6570\u662f\u7528\u4e8e\u6307\u5b9a\u8981\u6392\u9664\u626b\u63cf\u7684\u8def\u5f84\u6216\u6587\u4ef6\u7684\u547d\u4ee4\u3002<\/p>\n<p>\u56e0\u6b64\uff0c\u8fd9\u6761\u547d\u4ee4\u4f1a\u5c06\u8def\u5f84 &quot;C:\\JAVA&quot; \u6dfb\u52a0\u5230 Windows Defender \u7684\u626b\u63cf\u6392\u9664\u5217\u8868\u4e2d\uff0c\u4f7f\u5f97 Windows Defender \u4e0d\u4f1a\u626b\u63cf\u8be5\u8def\u5f84\u4e0b\u7684\u6587\u4ef6\u548c\u6587\u4ef6\u5939\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e6%96%b9%e6%b3%95%e4%ba%8c\"><\/span><strong>\u65b9\u6cd5\u4e8c<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>\u5b89\u88c5\u5176\u4ed6\u6740\u8f6f\u6765\u8ba9Windows Defender\u5931\u6548\uff0c\u5728\u4e0a\u4f20\u514d\u6740\u5bf9\u5e94\u6740\u8f6f\u4f46\u65e0\u6cd5\u7ed5\u8fc7Windows Defender\u7684\u6728\u9a6c\u3002<\/strong><\/p>\n<p>360\u5b89\u5168\u536b\u58eb\u4e3a\u4f8b\uff1a<\/p>\n<p>\u6211\u627e\u4e86\u597d\u4e45\u624d\u627e\u5230\uff0c\u5e0c\u671b\u5bf9\u4f60\u6709\u7528\uff0c\u6211\u4eb2\u624b\u6d4b\u8bd5\u7684\uff0c\u4ee5\u4e0b\u4e3a\u9759\u9ed8\u5b89\u88c5\u547d\u4ee4\u3002<\/p>\n<pre class=\"prettyprint linenums\" ><code>360aqws13.0.0.2109.exe \/S<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/img2023.cnblogs.com\/blog\/2411575\/202304\/2411575-20230411141209760-1624948647.png\" alt=\"\u56fe\u7247\" title=\"Windows Defender\uff1f\u522b\u7ed5\u4e86\uff01\u63d2\u56fe2\" \/><\/p>\n<p>\u7136\u540e\u5c31\u4f1a\u81ea\u52a8\u5b89\u88c5\u6210\u529f\uff0c\u684c\u9762\u56fe\u6807\u4e5f\u4f1a\u51fa\u6765\uff0c\u5982\u679c360\u6ca1\u6709\u81ea\u52a8\u6253\u5f00\u53ef\u4ee5\u547d\u4ee4\u884c\u6253\u5f00\u5373\u53ef\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6211\u4eec\u5e73\u5e38\u62ff\u5230webshell\u60f3\u8981c2\u4e0a\u7ebf\uff1f\u6076\u5fc3\u7684Windows Defender\u600e\u4e48\u529e\uff0c\u6d6a\u98d2\u82b110\u5206\u949f\u7ed9\u4f60\u5199\u4e00 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[],"class_list":["post-1345","post","type-post","status-publish","format-standard","hentry","category-24"],"_links":{"self":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/comments?post=1345"}],"version-history":[{"count":1,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1345\/revisions"}],"predecessor-version":[{"id":1346,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1345\/revisions\/1346"}],"wp:attachment":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/media?parent=1345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/categories?post=1345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/tags?post=1345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}