logo

Attackers Use Multiple Techniques to Bypass Reputation-Based Security

ID: d51a4875-4dea-5d6f-967b-78634c22937b

STIX ID: report--d51a4875-4dea-5d6f-967b-78634c22937b

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Elastic Security research shows attackers have developed reliable techniques to evade reputation-based Windows protections (SmartScreen and Smart App Control). Methods include abusing EV code signing, stripping the Mark of the Web from LNK files ("LNK stomping"), hijacking trusted script hosts to execute malicious content, and seeding benign binaries to build positive reputation; these techniques can allow malicious code to run despite reputation checks. The vendor recommends adding behavioral detection to monitor for credential access, in-memory evasion, persistence, and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.