New GhostTree Attack Causing EDR Products to Hang and Leave Files Unscanned
ID: fba36bf1-fe3a-594a-be12-2486c48dbd69
STIX ID: report--fba36bf1-fe3a-594a-be12-2486c48dbd69
Feed Name: cybersecurityNews.com
Varonis Threat Labs disclosed a technique named GhostTree that abuses NTFS junctions to create recursive directory loops, producing an exponential number of file paths that can cause endpoint detection and response (EDR) scanners to hang and fail to scan malicious files; researchers validated the approach against Windows Defender and Microsoft later issued a patch. The report details the attack variants, operational impact on file-system scanning, and recommends monitoring junction creation and anomalous recursive structures as defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
