Exploiting Windows MiniFilter to Bypass EDR Protection

They utilize the Filter Manager, which simplifies their development by providing a consistent interface for handling various file operations. Researchers at Tier Zero Security recently discovered that Windows MiniFilter can be abused by threat actors to bypass EDR.

Source: GBHackers

 


Date:

Categorie(s):