logo

Bypassing Cylance: Part 1 – Using VSAgent.exe

ID: 6831111e-db02-5696-9e91-473cbea11498

STIX ID: report--6831111e-db02-5696-9e91-473cbea11498

Feed Name: Black Hills Infosec Blog

Threat Score
55/100

Date Published: 2017-03-27

Date Updated: 2026-04-27

Author: BHIS

...
...

Black Hills Infosec tested a production Cylance deployment and demonstrated that their custom C2 client, VSAgent.exe, which hides commands in an ASP.NET ViewState parameter, executed and established command-and-control undetected in that environment. The post highlights that weak or missing application whitelisting and unrestricted access to cmd.exe and PowerShell ISE allowed the C2 to function, and recommends stronger application whitelisting and web content controls as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.