New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR

A new tool named GhostLocker has been released, demonstrating a novel technique to neutralize Endpoint Detection and Response (EDR) systems by weaponizing the native Windows AppLocker feature. Developed by security researcher zero2504, the tool highlights a fundamental architectural vulnerability in modern EDR solutions: their reliance on userland components for analysis and reporting.​ Unlike traditional EDR […]

The post New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: