April 19, 2023 ‘AuKill’ EDR killer malware abuses Process Explorer driver Driver-based attacks against security products are on the rise Threat Research
December 13, 2022 Signed driver malware moves up the software trust chain The criminals signed their AV-killer malware, closely related to one known as BURNTCIGAR, with a legitimate WHCP certificate Security OperationsThreat Research
October 04, 2022 Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse A fresh exploration of the malware uncovers a new tactic for bypassing security products by abusing a known driver vulnerability Threat Research
May 04, 2022 Attacking Emotet’s Control Flow Flattening Sweeping aside one obfuscation technique in a notorious strain of malware Products & Services