logo

Is This Thing On?

ID: 1447c33c-32a9-5ee8-b9c2-729e37f3370b

STIX ID: report--1447c33c-32a9-5ee8-b9c2-729e37f3370b

Feed Name: Black Hills Infosec Blog

Date Published: 2021-05-26

Date Updated: 2026-04-27

Author: BHIS

...
...

## Executive Summary This BHIS blog post provides step-by-step, non-malicious methods for testing antivirus and in-memory detection on sensitive systems — using the EICAR test file (saved with various extensions), storing EICAR in NTFS Alternate Data Streams, running the AMSI test string in PowerShell, and simulating behavior-based detection by creating an LSASS memory dump — intended as defensive guidance for administrators rather than a report of an incident.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.