Обложка канала

Sys-Admin & InfoSec Channel

Посты с ИТ-ресурсов, новости, тулзы, хакинг, администрирование, возможны бредовые посты с мемами, поздравлениями, может даже хейтами..

Sys-Admin & InfoSec Channel

3 года назад
Открыть в
/ ‘AuKill’ EDR killer malware abuses Process Explorer driver Over the past several months, Sophos X-Ops has investigated multiple incidents where attackers attempted to disable EDR clients with a new defense evasion tool we’ve dubbed AuKill. The AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system: — news.sophos.com/en-us/2…r-driver
‘AuKill’ EDR killer malware abuses Process Explorer driver

Driver-based attacks against security products are on the rise

Sophos News