Black Hills Information Security 09月29日 10:50
探究绕过终端安全产品的方法
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本篇内容聚焦于攻击者如何规避终端安全产品,并强调安全领域不存在一劳永逸的银弹。文章通过对多种终端安全产品的实际绕过技术进行演示,揭示了即使是先进的终端检测与响应(EDR)产品也存在配置不当导致的安全隐患。 webcast系列旨在提醒业界,安全防护依赖于多层防御和持续的配置优化与监控,而非单一产品。演示涵盖了包括Carbon Black、Cisco AMP、CylancePROTECT、Windows Defender等多种产品的绕过技巧,并探讨了PowerShell AMSI绕过、Windows Subsystem for Linux(WSL)以及利用HTTP Web Cradle进行文件下载等高级技术,旨在提升安全意识,强调配置和监控的重要性。

🛡️ **终端安全产品并非万能:** 文章通过实际演示,揭示了包括Carbon Black、Cisco AMP、CylancePROTECT和Windows Defender在内的多种先进终端安全产品均存在被攻击者绕过的可能性。这有力地反驳了单一产品即可实现绝对安全的观点,强调了安全防护的复杂性。

🔧 **配置不当是关键弱点:** 许多高级终端安全产品拥有复杂的配置选项,但若配置不当,反而可能削弱其整体防护效能,甚至为攻击者提供可乘之机。因此,细致的配置管理和持续的监控至关重要。

🔍 **多样的绕过技术:** 演示涵盖了多种绕过技术,包括但不限于PowerShell AMSI绕过(如Rhino)、利用Windows Subsystem for Linux(WSL)、以及通过PowerShell HTTP Web Cradle进行恶意文件下载等。这些技术展示了攻击者不断演变的策略。

💡 **持续监控与多层防御的重要性:** webcast的核心信息在于强调“安全配置和监控仍然至关重要”。它呼吁业界认识到,有效的安全策略必须建立在对产品配置的深入理解、持续的监控以及多层防御体系的基础上,而非仅仅依赖于购买最新的安全工具。







Want to learn how attackers bypass endpoint products?



Slides for this webcast can be found here: https://www.blackhillsinfosec.com/wp-content/uploads/2020/09/SLIDES_SacredCashCowTipping2020.pdf



3:41 – Alternate Interpreters



9:19 – Carbon Black Config Issue



15:07 – Cisco AMP EDR – Quick and Easy Bypass



18:24 – PowerShell AMSI Bypass – Rhino



19:07 – CylancePROTECT Bypass



24:14 – Windows Defender and Carbon Black Bypass



30:36 – Windows Subsystem for Linux



39:59 – PowerShell HTTP Web Cradle for Downloads



Last year we came to the conclusion that we are going to keep going with the Sacred Cash Cow Tipping Webcast series. Why? Because many in the industry still believe that security is something that can be achieved through the purchase of a single product.



To that end, we feel there is still a need to deconstruct certain parts of security (like AV) and show that there are always structural weaknesses in every security product that is implemented.



This is becoming even more important now that many of the advanced endpoint products are not just fire-and-forget but have an endless array of different configurations that enable a company to shoot themselves in the foot by reducing the overall effectiveness of these products.



So, yes, Sacred Cash Cow Tipping is more important than ever.



To that end, our next webcast will be on bypassing endpoint security products. The goal of this webcast is to help show people that there is still no silver bullet in security. We also desperately want to show that configuration and monitoring still matters.



This is our first webcast of the year. It may run longer than 60 minutes. It will be recorded. We will have a team of Black Hills Testers answering questions throughout the webcast. We have room for 3,000 attendees, so you will be able to attend live if you want.















Ready to learn more?



Level up your skills with affordable classes from Antisyphon!



Pay-Forward-What-You-Can Training



Available live/virtual and on-demand





Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

终端安全 安全绕过 EDR 配置管理 网络安全 Endpoint Security Security Bypass EDR Configuration Management Cybersecurity
相关文章