Defense-Evasion
2 posts

GhostTree Makes Windows Defender Stop Scanning With Two Lines of Code
GhostTree makes Windows Defender stop scanning. Two lines of code, no admin rights, and malware sitting right next to it goes completely undetected. A Varonis …

MSBuild LOLBin: How Hackers Run Malware on Windows Without Leaving a Trace
MSBuild.exe is a LOLBin, a legitimate Windows tool being abused to run malware on fully patched machines without dropping a single file on disk, and Windows …