GhostLock: New Attack Technique Locks Enterprise Files Like Ransomware — Without Any Encryption
GhostLock is a newly disclosed attack technique that uses standard Windows file-locking behavior to paralyze enterprise SMB file shares without encrypting a single byte. Requiring only a standard domain user account, it evades every conventional ransomware defense — canary files, EDR, NDR, and SIEM — while achieving the same business disruption as encryption ransomware.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.