People ask me all the time: As an advanced APT how would you persist, avoid detection and do you think that technique is actively used currently? Nah, they dont- and if they did I would ask them to leave me alone. I did have some random thoughts about it in the shower though.
-
-
Obscurity, evasaion of AV and persistent execution. But what about stuff like c&c- surviving reboots etc. Well, the filtering platform could be a fit for that, kernel mode, interpeted and obscure. You could survive reboots as an ummm firewall rule I guess?
Show this thread -
You can intercept and inject traffic into network as you want- bypass other filters, AV, endpoints etc. while not being listed as a loaded driver/nor a running exe/dll in any lists that could be inspected. Few people would even know how to approach detection of such a beast.
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.