Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support

Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of access, the tools on the machine stop reliably protecting it. Ransomware crews run the technique as a step before they deploy a payload, a … More →

This article has been indexed from Help Net Security

Read the original article: