New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File
Bitdefender researchers have detailed how Windows ‘bind links’ — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to redirect trusted file paths to malicious code invisibly. The technique, covering File-Binding, Process-Binding, and Silo-Binding, can blind EDR sensors and bypass AMSI, AppLocker, and Sysmon logging.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.