TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Bypassing Cylance: Part 1 – Using VSAgent.exe

BHIS · 2017-03-27 · Read original ↗

ATT&CK techniques detected

1 predictions
T1071Application Layer Protocol
38%
“a well - formed html page to communicate commands and their results between the c2 server and client. the viewstate parameter is commonly used in asp. net web applications to maintain state between the client and the server. because this field is so commonly observed and is base6…”

Summary

David Fletcher // Recently, we had the opportunity to test a production Cylance environment. Obviously, each environment is going to be different and the efficacy of security controls relies largely […]

The post Bypassing Cylance: Part 1 – Using VSAgent.exe appeared first on Black Hills Information Security, Inc..