InfinitumIT

Blog

Latest insights from the threat landscape

Analysis Report

Trusted Process Abuse: Why Doesn't MDE See the Command Hidden Behind vmtoolsd?

The anatomy of an EDR blind spot on Microsoft Defender for Endpoint: why the PowerShell command spawned under vmtoolsd via vSphere Guest Operations doesn't raise an alarm in DeviceProcessEvents, and how to close the gap with an Advanced Hunting query and a Custom Detection Rule.

03.07.2026 · 7 min

Analysis Report

Check Point Harmony Endpoint — Trusted Process, the EDR Blind Spot: The VMware vmtoolsd Case

Why does Check Point Harmony stay silent on commands arriving via vSphere Guest Operations? Closing the gap step by step with a Threat Hunting query, a Behavioral Protection Custom Rule, and a 30-day backtest window.

03.07.2026 · 6 min

Analysis Report

The Dark Side of the Hypervisor: EDR/XDR Bypass via VMware Guest Operations — A FortiEDR Case Study

An analysis of VMware Guest Operations abuse via the signed vmtoolsd process on FortiEDR — why the Trusted Parent design leaves this vector silent, how to catch it with a Threat Hunting query turned into a Custom Rule, and Defense-in-Depth recommendations.

03.07.2026 · 6 min

Analysis Report

Trusted Process Abuse: The EDR Blind Spot — A Cortex XDR Case Study on VMware Tools (vmtoolsd)

An analysis of Guest Operations abuse via the signed and trusted vmtoolsd with Palo Alto Cortex XDR — a CGO-based XQL query, a BIOC rule that persists the detection, and a Restrictions (Custom Prevention) profile configuration for real-time blocking.

03.07.2026 · 9 min

Analysis Report

Trusted Process: Detecting VMware Guest Operations Abuse with CrowdStrike Falcon

Detecting Guest Operations abuse via the signed and trusted vmtoolsd.exe with CrowdStrike Falcon — endpoint telemetry, Advanced Event Search / LogScale hunting query, a recommended Custom IOA rule, and tuning steps.

03.07.2026 · 7 min

Analysis Report

Sentinelone — Trusted Process Abuse: The EDR Blind Spot — VMware Tools (vmtoolsd)

How can signed and trusted processes bypass EDR behavioral detection? Analysis of Guest Operations abuse via VMware Tools' vmtoolsd component using SentinelOne DeepVisibility, plus a custom detection rule.

03.07.2026 · 6 min

Analysis Report

CVE-2026-41651 — Pack2TheRoot: A Race Condition to Root via PackageKit

Pack2TheRoot vulnerability discovered in the default PackageKit service on Linux — three separate bugs (unconditional flag overwrite, silent state rejection, late flag read) combine so an ordinary user can install arbitrary packages as root. Technical analysis of the Time-of-Check / Time-of-Use race condition.

04.06.2026 · 9 min

Zafiyet Yönetimi

Kerberos: Active Directory Attack Surface and Hardening Guide

Kerberos protocol at the heart of Active Directory: KDC, TGT, Service Ticket flow; AS-REP Roasting, Kerberoasting, Golden Ticket and delegation models; practical hardening steps.

04.06.2026 · 12 min

Log Yönetimi ve 5651

Log Parsing in QRadar with DSM: A Practical Walkthrough on a Real-World Scenario

IBM QRadar üzerinde DSM Editor ile tanınmayan logları adım adım parse edip QID ile eşleştirerek anlamlı event'lere dönüştürmenin tam yol haritası.

05.05.2026 · 8 min

Makaleler

IBM QRadar User Guide

Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.

11.03.2026 · 1 min

Makaleler

FortiNDR: Next-Generation Network Threat Detection and Response

Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.

24.02.2026 · 1 min

Makaleler

Zero-Day Attacks: Discovery, Monitoring and Defense Methods

Zero-Day attacks are cyber attacks that target security vulnerabilities in computer software or operating systems that have not yet been discovered and patched. The term "Zero-Day" refers to the days before the vulnerability was discovered.

10.08.2023 · 1 min

Our team certifications

Experts accredited by SANS, Offensive Security, EC-Council, CompTIA, ISACA, CREST, and INE.

SANS GPEN
SANS GWAPT
SANS GICSP
SANS GRTP
SANS GCIH
SANS GSEC
Offensive Security OSCP
Offensive Security OSWP
EC-Council CEH
CompTIA Security+
ISACA CISM
ISACA CISA
CREST CRT
INE eWPTX
Fortinet FCP Secure Networking
Fortinet FCP Cloud Security
Fortinet FCP Security Operations
Fortinet FCSS Secure Networking
Fortinet FCSS SASE
Fortinet FCSS Cloud Security
Fortinet FCSS Security Operations
IBM QRadar Admin
SANS GPEN
SANS GWAPT
SANS GICSP
SANS GRTP
SANS GCIH
SANS GSEC
Offensive Security OSCP
Offensive Security OSWP
EC-Council CEH
CompTIA Security+
ISACA CISM
ISACA CISA
CREST CRT
INE eWPTX
Fortinet FCP Secure Networking
Fortinet FCP Cloud Security
Fortinet FCP Security Operations
Fortinet FCSS Secure Networking
Fortinet FCSS SASE
Fortinet FCSS Cloud Security
Fortinet FCSS Security Operations
IBM QRadar Admin

Cookie usage

We only use essential session and language preference cookies; no third-party tracking cookies. For details, see our Cookie Policy and KVKK Privacy Notice.