top | item 43960211

(no title)

s4mbh4 | 9 months ago

Why would you want to disable WSC?

discuss

order

devrandoom|9 months ago

Performance reasons? Malware development? Hacking?

fransje26|9 months ago

Is there a more performant, less resource-crippling, antivirus for Windows?

Hilift|9 months ago

If you are a threat actor, you could get lucky and there isn't another Endpoint Detection and Response product installed, which would almost certainly intercept this.

If you are an EDR vendor, this is an obfuscated API call that EDR vendors can use to suppress or disable the Windows Firewall. CrowdStrike for example, can do either I believe, use Windows Firewall or use their implementation.

xyst|9 months ago

It’s my hardware. I’ll do what I want with it, m8.

Simple as that.

AStonesThrow|9 months ago

Well this is a straightforward sentiment with a real "my body, my choice" ring to it, isn't it? Until it isn't.

Perhaps your hardware, when connected to a network, has real effects on the rest of that network. What if your system joined a botnet and began DDOS activities for payment? What if your system was part of a residential proxy network, and could be rented in the grey market for any kind of use or abuse of others' systems? What if your system became a host for CSAM or copyright-violating materials, unbeknownst to you, until the authorities confiscated it?

And what if your hardware had a special privileged location on a corporate network, or you operated a VPC with some valuable assets, and that was compromised and commandeered by a state-level threat actor? Is it still "your hardware, your choice"? Or do your bad choices affect other people as well?

nicman23|9 months ago

because all antivirus softwares are at least powerviruses.

i do not care for anyone baby sitting me telling me that netcat.exe is a no no

ahoka|9 months ago

Because why would you want to rootkit yourself on purpose?