Bypassing Cylance: Part 1 – Using VSAgent.exe
ID: 6831111e-db02-5696-9e91-473cbea11498
STIX ID: report--6831111e-db02-5696-9e91-473cbea11498
Feed Name: Black Hills Infosec Blog
Black Hills Infosec tested a production Cylance deployment and demonstrated that their custom C2 client, VSAgent.exe, which hides commands in an ASP.NET ViewState parameter, executed and established command-and-control undetected in that environment. The post highlights that weak or missing application whitelisting and unrestricted access to cmd.exe and PowerShell ISE allowed the C2 to function, and recommends stronger application whitelisting and web content controls as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
