TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

An unexpected journey into Microsoft Defender's signature World

175 点作者 serhack_10 个月前

6 条评论

Angostura10 个月前
A note to the author: if you are going to include “ EDR and EPP” in the intro, please spell them out on first use
评论 #40854851 未加载
评论 #40854580 未加载
评论 #40854891 未加载
FrostKiwi10 个月前
Great deep dive! Always wondered about the details around this topic.<p>Did a bit of red teaming around the topic of reverse shells and privilege escalation and was pleasantly surprised, how much Windows Defender catches. Our IT Department recently switched away from a paid McAfee service doing end point security, which failed to detect unauthorized access in many instances.<p>Also, I totally read the intro as &quot;addressing the ERP use-case&quot;
评论 #40858761 未加载
评论 #40856593 未加载
评论 #40857039 未加载
vegadw10 个月前
I wish that on a positive find Defender had a &quot;for the nerds&quot; section that says what exactly was found. Was there a URL Regex match, like this article gives an example for? Tell me that. I get enough false positives that I want to be able to vet them myself, but that&#x27;s hard to do without just trusting the source if all get is a &quot;This has been quarantined&quot; without telling me why beyond a broad class of types of malware.
RachelF10 个月前
Nice big attack surface there. I wonder what&#x27;s to stop someone modifying the vdx virus definition files to include something like Edge.exe or Explorer.exe?
banish-m410 个月前
MDE plan 2 had problems where MS was pushing out under-tested signatures. One time, they pushed out defs that deleted all menu shortcuts for some users, leading them to believe all of their software had been uninstalled.
InDubioProRubio10 个月前
Thaught it would mention at least the slow-down bug, that slows some systems to a crawl as soon as defender scans some folders.