Attackers Use Multiple Techniques to Bypass Reputation-Based Security
ID: d51a4875-4dea-5d6f-967b-78634c22937b
STIX ID: report--d51a4875-4dea-5d6f-967b-78634c22937b
Feed Name: Dark Reading
Elastic Security research shows attackers have developed reliable techniques to evade reputation-based Windows protections (SmartScreen and Smart App Control). Methods include abusing EV code signing, stripping the Mark of the Web from LNK files ("LNK stomping"), hijacking trusted script hosts to execute malicious content, and seeding benign binaries to build positive reputation; these techniques can allow malicious code to run despite reputation checks. The vendor recommends adding behavioral detection to monitor for credential access, in-memory evasion, persistence, and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
