Shoutout to the great @lkarlslund for this cool thing;

His own tl;dr: unprivileged user -> Defender removal on physical machine

https://github.com/lkarlslund/nifo

#NukeItFromOrbit #nifo #RemoveDefender #Microsoft #SecurityBoltedOnNotBuiltIn

GitHub - lkarlslund/nifo: Nuke It From Orbit - remove AV/EDR with physical access

Nuke It From Orbit - remove AV/EDR with physical access - lkarlslund/nifo

GitHub