91% of critical incidents involve known, legitimate binaries like PowerShell

Discussion in 'other security issues & news' started by Minimalist, Jun 28, 2018.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.helpnetsecurity.com/2018/06/28/incidents-legitimate-binaries/
     
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    IBM missed a couple of additional SysInternals tools that are often used maliciously. In addition to PsExec, PsLoggedOn and ProcDump can also be used for remote execution, interactive logon enumeration, and dumping of credentials within lsass.exe address space respectively.
     
  4. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Last edited: Feb 26, 2019
  5. guest

    guest Guest

    Hackers Are Loving PowerShell, Study Finds
    March 27, 2019
    https://www.securityweek.com/hackers-are-loving-powershell-study-finds
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.