SecBoard
Zurück zur Übersicht

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

BleepingComputer·
Originalartikel lesen bei BleepingComputer

GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected. [...]

MITRE ATT&CK Kill Chain (2 Techniken)

Themen
Security