There ARE ways of evading endpoint security, but...

There ARE ways of evading endpoint security, but...

In my article that explains that the hackers can get around endpoint security but that you still need it, I give some examples of exploits that can get around endpoint security.

Today there was an article in SC Media describing an exploit that was just reported in Hacker News that could evade endpoint security on windows.

Essentially what it does is take advantage of what I think is an obscure feature of Windows (aren't they all?) called a reparse tag. But that's not the point.

The point is this. This can only happen IF the exploit has already figured out how to get admin access. So...

If your first levels of protection such as firewalls, antivirus, behavioral analysis, UEM, and so forth were in place, this might never happen.

So rest easier if you have these things in place. But if you don't? Well...


要查看或添加评论,请登录

Michael Toback的更多文章

社区洞察

其他会员也浏览了