Antivirus

Security community tools help intruders

To many ordinary home users and businesses, security software is nothing more than having antivirus protection and or endpoint security software. However, for enterprises the situation is more complex.I expect adversaries will continue to leverage publicly released tools, often developed by penetration testers and security researchers, to compromise and control targets worldwide. This trend, publicized most…


To many ordinary home users and businesses, security software is nothing more than having antivirus protection and or endpoint security software. However, for enterprises the situation is more complex.

I expect adversaries will continue to leverage publicly released tools, often developed by penetration testers and security researchers, to compromise and control targets worldwide. 

This trend, publicized most effectively by Mandiant’s Andrew Thompson, turns standard defensive thinking upside down. Unfortunately, it is difficult for those who work on the offensive side of the security team to recognize that this is the case.

The mantra for the past decade has been to “make intrusions more costly for the adversary.” One of the costs an intruder used to have to consider was the development of tools and techniques to compromise and control targets. 

However, today the majority of intruders operate publicly released tools to accomplish their goals. This means that intruders can radically decrease their research and development costs, as that burden has already been borne by penetration testers and security researchers.

About the author

Richard Bejtlich is principal security strategist at Corelight.

Public offensive tool releases

The argument in support of public offensive tool release usually offered by penetration testers and security researchers is that they are simply recreating capabilities already known and perhaps utilized by top tier intrusion groups. 

By releasing new capabilities, the argument goes, defenders learn what is possible and can develop mitigations that work against penetration testers and actual adversaries. 

Their scenario plays out in the following manner:

  • An enterprise deploys assets in

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

The Main Street Tech Report: Microsoft Says Third Party Antivirus Software Is No Longer Needed

Welcome to The Main Street Tech Report, your weekly roundup of the most important small business technology news. Here are five key developments in AI, automation, and digital tools that emerged this week-and what they mean for your business. Microsoft Officially Says You Don’t Need Extra Antivirus on Windows 11 Hans-Christian Dirscherl of PCWorld reports

Welcome to The Main Street Tech Report, your weekly roundup of the most important small business technology news. Here are five key developments in AI, automation, and digital tools that emerged this week-and what they mean for your business. Microsoft Officially Says You Don’t Need Extra Antivirus on Windows 11 Hans-Christian Dirscherl of PCWorld reports
Read More

Continue Reading
Antivirus

Researchers warn Microsoft Defender vulnerability is already being exploited

A security researcher known as Chaotic Eclipse recently disclosed a vulnerability dubbed “Red Sun” affecting Microsoft Defender Antivirus. While criticizing Microsoft’s handling of the issue, Chaotic Eclipse explained that their proof-of-concept code could potentially be used to bypass Defender’s protections. The researcher also claimed that malicious actors have already begun…Read Entire Article…

A security researcher known as Chaotic Eclipse recently disclosed a vulnerability dubbed “Red Sun” affecting Microsoft Defender Antivirus. While criticizing Microsoft’s handling of the issue, Chaotic Eclipse explained that their proof-of-concept code could potentially be used to bypass Defender’s protections. The researcher also claimed that malicious actors have already begun…Read Entire Article…
Read More

Continue Reading
Antivirus

Signed software abused to deploy antivirus-killing scripts

A digitally signed adware tool has deployed payloads running with SYSTEM privileges that disabled antivirus protections on thousands of endpoints, some in the educational, utilities, government, and healthcare sectors. …

A digitally signed adware tool has deployed payloads running with SYSTEM privileges that disabled antivirus protections on thousands of endpoints, some in the educational, utilities, government, and healthcare sectors. …
Read More

Continue Reading
Antivirus

Stop falling for scams when Norton’s antivirus software is 70% off right now

For a limited time, you can get a year of Norton 360 Premium, which includes a VPN and scam protection, at a major discount…

For a limited time, you can get a year of Norton 360 Premium, which includes a VPN and scam protection, at a major discount…
Read More

Continue Reading