Attackers install AV to disable security

Discussion in 'other security issues & news' started by BoerenkoolMetWorst, Nov 5, 2024.

  1. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,943
    Location:
    Outer space
    Rapid7 has a blog post on how Sharepoint was compromised:
    https://www.rapid7.com/blog/post/20...harepoint-compromise-ir-tales-from-the-field/

    Interestingly, they installed a legit AV to crash existing security software:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.