Executables that bypass Windows AV VS those that don't (nc, plink etc.)

@gnothiseauton I dont think you were speaking half truths, it was the information you’d established from experimentation against a theory! That is vital.

I think the deeper issue is that there are so many variables here it is hard for any one-person to be 100% sure. As I said, I genuinely didn’t even realise there could be a problem until people mentioned it in the forums. When I did it, it “just worked.”

I’d like to think that if it is AV, the version of nc in a default Kali 2019 build would be in the signatures before they added ones from github pages - but who knows…

A couple of people who have DM’d me about this have used upload techniques which are guaranteed to break the file, but I dont think that’s the case here.