Blog
Latest insights from the threat landscape
Trusted Process Abuse: Why Doesn't MDE See the Command Hidden Behind vmtoolsd?
The anatomy of an EDR blind spot on Microsoft Defender for Endpoint: why the PowerShell command spawned under vmtoolsd via vSphere Guest Operations doesn't raise an alarm in DeviceProcessEvents, and how to close the gap with an Advanced Hunting query and a Custom Detection Rule.
03.07.2026 · 7 min
Analysis ReportCheck Point Harmony Endpoint — Trusted Process, the EDR Blind Spot: The VMware vmtoolsd Case
Why does Check Point Harmony stay silent on commands arriving via vSphere Guest Operations? Closing the gap step by step with a Threat Hunting query, a Behavioral Protection Custom Rule, and a 30-day backtest window.
03.07.2026 · 6 min
Analysis ReportThe Dark Side of the Hypervisor: EDR/XDR Bypass via VMware Guest Operations — A FortiEDR Case Study
An analysis of VMware Guest Operations abuse via the signed vmtoolsd process on FortiEDR — why the Trusted Parent design leaves this vector silent, how to catch it with a Threat Hunting query turned into a Custom Rule, and Defense-in-Depth recommendations.
03.07.2026 · 6 min
Analysis ReportTrusted Process Abuse: The EDR Blind Spot — A Cortex XDR Case Study on VMware Tools (vmtoolsd)
An analysis of Guest Operations abuse via the signed and trusted vmtoolsd with Palo Alto Cortex XDR — a CGO-based XQL query, a BIOC rule that persists the detection, and a Restrictions (Custom Prevention) profile configuration for real-time blocking.
03.07.2026 · 9 min
Analysis ReportTrusted Process: Detecting VMware Guest Operations Abuse with CrowdStrike Falcon
Detecting Guest Operations abuse via the signed and trusted vmtoolsd.exe with CrowdStrike Falcon — endpoint telemetry, Advanced Event Search / LogScale hunting query, a recommended Custom IOA rule, and tuning steps.
03.07.2026 · 7 min
Analysis ReportSentinelone — Trusted Process Abuse: The EDR Blind Spot — VMware Tools (vmtoolsd)
How can signed and trusted processes bypass EDR behavioral detection? Analysis of Guest Operations abuse via VMware Tools' vmtoolsd component using SentinelOne DeepVisibility, plus a custom detection rule.
03.07.2026 · 6 min
Analysis ReportCVE-2026-41651 — Pack2TheRoot: A Race Condition to Root via PackageKit
Pack2TheRoot vulnerability discovered in the default PackageKit service on Linux — three separate bugs (unconditional flag overwrite, silent state rejection, late flag read) combine so an ordinary user can install arbitrary packages as root. Technical analysis of the Time-of-Check / Time-of-Use race condition.
04.06.2026 · 9 min
Zafiyet YönetimiKerberos: Active Directory Attack Surface and Hardening Guide
Kerberos protocol at the heart of Active Directory: KDC, TGT, Service Ticket flow; AS-REP Roasting, Kerberoasting, Golden Ticket and delegation models; practical hardening steps.
04.06.2026 · 12 min
Log Yönetimi ve 5651Log Parsing in QRadar with DSM: A Practical Walkthrough on a Real-World Scenario
IBM QRadar üzerinde DSM Editor ile tanınmayan logları adım adım parse edip QID ile eşleştirerek anlamlı event'lere dönüştürmenin tam yol haritası.
05.05.2026 · 8 min
MakalelerIBM QRadar User Guide
Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.
11.03.2026 · 1 min
MakalelerFortiNDR: Next-Generation Network Threat Detection and Response
Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.
24.02.2026 · 1 min
MakalelerZero-Day Attacks: Discovery, Monitoring and Defense Methods
Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.
10.08.2023 · 1 min