Description
This module will generate an HTA file that writes and compiles a JScript.NET file containing shellcode on the target machine. After compilation, the generated EXE will execute the shellcode without interference from Windows Defender.
It is recommended that you use a payload that uses RC4 or HTTPS for best experience.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use evasion/windows/windows/defender_js_htamsf undefined(defender_js_hta) > show actions ...actions...msf undefined(defender_js_hta) > set ACTION < action-name >msf undefined(defender_js_hta) > show options ...show and set options...msf undefined(defender_js_hta) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub