Disabling AV With Process Suspension
ID: b44a3ca8-7f17-5e80-af38-d2baf3cfe20e
STIX ID: report--b44a3ca8-7f17-5e80-af38-d2baf3cfe20e
Feed Name: TrustedSec blog
Threat Score
This research post demonstrates a technique to suspend Windows Defender and other protected processes using beacon object files to perform LSASS minidumps (enabling Mimikatz use), highlighting an oversight where suspend/resume access is permitted while terminate is blocked; the author warns of system instability and logging blind spots, encourages vendors to close the gap, and suggests Sysmon-based detections as partial mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
