Attackers are leaning on a new EDR killer malware that can shut down 59 widely used endpoint security products by misusing a kernel driver that once shipped with Guidance Software’s EnCase digital forensics tool, Huntress researchers warn. This particular driver is legitimate but its certificate expired and was revoked more than ten years ago. Even so, Windows still allows it to load. The attack Huntress’ security experts spotted this intrusion earlier this month, and discovered … appeared first on Help Net Security.
Ähnliche Beiträge
Auch interessante Nachrichten Why a decade-old EnCase driver still works as an EDR killer
Thematisch verwandte Begriffe: decadeold, EnCase, driver, still · 6 Treffer
Stopping Vulnerable Driver Attacks
Forget vulnerable drivers - Admin is all you need
Click, Click… Boom! Automating Protections Testing with Detonate
Automating GOAD and Live Malware Labs
NETWIRE Dynamic Configuration Extraction
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
SOCIAL SHARE CARD GENERATOR