4 ms·
Most of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise. Without something
by CAP_NET_ADMIN 3y ago
Most of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise. Without something like that running, you're basically tied to manual review of systems running at the moment. Making malware for such scenarios is basically making a Base64-encoded script in the language of your choice and then exploiting something(either the user or some software) to get it to execute.
I know, because I've been writing small malware toys and it got blasted by both Bitdefender and ESET.
- hulitu 3y ago> Most of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise Ransomware runs just fine on corporate computers with the latest and greatest "antivirus" software. I really lost hope some 10 years ago, when i saw that i have to manually remove malware from memory sticks, because macaffe was clueless. After more than a year they released an update that will detect and remove the malware (it was a virus speading through autorun.inf with exe names which did not have any sense like jhghjjj.exe)
- consumer451 3y agoI can't speak to that particular attack vector today, but it's interesting that McAfee isn't even on this Gartner chart, and that Microsoft is now a leader. Things have really changed in that space. https://www.cybereason.com/blog/cybereason-named-a-leader-in-2022-gartner-magic-quadrant-for-endpoint-protection-platforms https://www.cybereason.com/blog/cybereason-named-a-leader-in...
- CAP_NET_ADMIN 3y agoCorporate Ransomware attacks typically use 0-days and social engineering to achieve goals. No system is perfect, but a system in place is better than not having anything in place. Things have changed in the last 10 years. Long gone are the days of only using signature databases. https://attackevals.mitre-engenuity.org/results/enterprise?vendor=bitdefender&vendor=microsoft&vendor=mcafee&evaluation=wizard-spider-sandworm&scenario=1 https://attackevals.mitre-engenuity.org/results/enterprise?v...