Is This Thing On?
ID: 1447c33c-32a9-5ee8-b9c2-729e37f3370b
STIX ID: report--1447c33c-32a9-5ee8-b9c2-729e37f3370b
Feed Name: Black Hills Infosec Blog
## Executive Summary This BHIS blog post provides step-by-step, non-malicious methods for testing antivirus and in-memory detection on sensitive systems — using the EICAR test file (saved with various extensions), storing EICAR in NTFS Alternate Data Streams, running the AMSI test string in PowerShell, and simulating behavior-based detection by creating an LSASS memory dump — intended as defensive guidance for administrators rather than a report of an incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
