9 ms·
I would like to inform you that none of the AV product on the market will be able to protect you from piping a bad script from the web. Case closed.
by bugbuddy 2y ago
I would like to inform you that none of the AV product on the market will be able to protect you from piping a bad script from the web. Case closed.
- darkwater 2y agoCrowdstrike agent is theoretically able to detect that what you just pipe-installed is now connecting to a known command and control server and can act accordingly.
- pas 2y agoyes, as any competent classic old fart network-wide IPS/IDS endpoint security is a great utopia to strive for, but to get there we ought to starts with having secure by default endpoints.
- yourusername 2y agoIf your malicious script starts doing things like running well known payloads or trying to move laterally or access things it really shouldn't be trying to access AV will flag/block it.
- saagarjha 2y agoWhat happens when the malicious script tries a not-very-well-known payload? Hint: nothing good.
- yourusername 2y agoNo one is suggesting it is 100% coverage but you would be suprised at the ammount of things XDR detects and prevents in a average organization with average users. Including the people who can't stop clicking YourGiftcard.pdf.exe
- saagarjha 2y agoI am not against trying to protect against people who do that. The problem is that you pay XDR big bucks to stop a lot more than that, and this mostly doesn't work.
- tikkabhuna 2y agoCarbon Black will block any executables it pulls down though. And I think it may also block scripts as well. Executables have to be whitelisted before they can run. Its an extremely strict approach, but it does address the situation you're talking about.
- saagarjha 2y agoScripts are not executables
- tikkabhuna 2y agoAgreed, but Carbon Black can stop scripts from running.
- saagarjha 2y agoIf it lets you spawn a shell I would bet money against that
- tikkabhuna 2y agoIf you write a batch file on a Windows PC with Carbon Black on it, you will not be able to run it. Of course there is customisation available to tweak what is/isn't allowed.
- saagarjha 2y agoYes, but that's like 1% of the actual surface area for "running a script". I am not a Windows expert but on, say, Linux you can overwrite a script that someone has already run, or modify a script that is already running, or use an interpreter that your antivirus doesn't know about, or sit around and wait for a script to get run and then try to swap yourself into the authorization that gets granted for that, or…there's a whole lot of things. I assume Windows has most of the same problems. My confidence in Carbon Black stopping this is quite low.
- BrandonLive 2y agoThat’s both untrue and missing the point. In a perfect world, AV software wouldn’t be necessary. We don’t live in a perfect world. So we need defense-in-depth, covering prevention, mitigation, and remediation.