Bypassing Cylance: Part 2 – Using DNSCat2
ID: 0c7d2af6-3ad1-52fe-a4fd-6cbad9dabca1
STIX ID: report--0c7d2af6-3ad1-52fe-a4fd-6cbad9dabca1
Feed Name: Black Hills Infosec Blog
Threat Score
This report documents testing of DNSCat2 to establish DNS-based command-and-control against a Cylance-protected environment; encrypted connections were dropped while unencrypted sessions succeeded and were not detected by Cylance, demonstrating the need for layered defenses such as application whitelisting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
