Bypassing Cylance: Part 4 – Metasploit Meterpreter & PowerShell Empire Agent
ID: d5934414-3557-5497-bf9a-f833078bb935
STIX ID: report--d5934414-3557-5497-bf9a-f833078bb935
Feed Name: Black Hills Infosec Blog
This Black Hills InfoSec report documents hands-on testing of Cylance endpoint protection: Metasploit Meterpreter payloads were repeatedly detected and blocked, but renaming the native PowerShell executable allowed a PowerShell Empire agent to execute and establish C2. With default settings the agent was identified after ~3 hours, but after adding jitter and non-default resources the Empire beacon evaded detection for more than 24 hours, illustrating an AV-evasion TTP and the need for defense-in-depth.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
