As cited
Copy frozen at (site build).
threat intel
Abusing Trusted Applications with Nested Execution
A talk at DerbyCon 7.0 discussed techniques for evading persistence enumeration tools by abusing trusted applications through nested execution. The presentation covered evasion methods that leverage legitimate system applications, a topic gaining attention in the infosec community but lacking detailed analysis on the mechanics and discovery process for identifying suitable host applications.
Why it matters: Defenders and security teams need to understand how attackers abuse trusted applications to maintain persistence and evade detection tools, informing defensive strategies and monitoring capabilities.
- Source published
- First seen by Cybersecurity Tracker