all InfoSec news
Skrull - A Malware DRM, That Prevents Automatic Sample Submission By AV/EDR And Signature Scanning From Kernel
Jan. 1, 2022, 8:30 p.m. | noreply@blogger.com (Unknown)
KitPloit - PenTest Tools! www.kitploit.com
Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting technique. Also, launchers are totally anti-copy and naturally broken when got submitted.
It's a proof-of-concept of the talk of ROOTCON & HITCON 2021, check out Skrull Like A King: From File Unlink to Persistence and Skrull Like A King:從重兵看守的天眼防線殺出重圍 :)
note that currently support only x64 PE now, due …
av bypass antivirus drm edr injection kernel malware scanning signature skrull
More from www.kitploit.com / KitPloit - PenTest Tools!
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Information Security Engineers
@ D. E. Shaw Research | New York City
Staff DFIR Investigator
@ SentinelOne | United States - Remote
Senior Consultant.e (H/F) - Product & Industrial Cybersecurity
@ Wavestone | Puteaux, France
Information Security Analyst
@ StarCompliance | York, United Kingdom, Hybrid
Senior Cyber Security Analyst (IAM)
@ New York Power Authority | White Plains, US