Blog
Latest insights from the threat landscape
WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Microsoft Defender for Endpoint
A live lab test of the CVE-2026-63030 wp2shell chain against MDE for Linux: no configuration — including the strictest protection profile — produced an alert. Advanced Hunting queries (DeviceFileEvents + DeviceProcessEvents) turned into a Custom Detection Rule that catches the web-server → shell/discovery/download behavior.
21.07.2026 · 7 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Check Point Harmony Endpoint
The CVE-2026-63030 wp2shell vulnerability analyzed on Check Point Harmony Endpoint with InfinitumIT lab test findings: the default policy raised no alerts through STEP 1-4 of the attack chain. Five Custom Detection Rules deployable as filter-chip bookmarks in the CP XDR Threat Hunting page, plus one retrospective hunt query.
20.07.2026 · 14 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Cortex XDR
The CVE-2026-63030 wp2shell vulnerability disclosed on 17 July 2026 — a pre-auth RCE chaining route confusion with SQL injection on the WordPress REST API batch endpoint. Five BIOCs plus one retrospective hunt query deployable on Cortex XDR, with a validated Behavioral Threat Protection kernel-level inline block against the T1036.004 Masquerading step in the InfinitumIT lab.
20.07.2026 · 10 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with SentinelOne
An analysis of the WordPress Core CVE-2026-63030 WP2Shell vulnerability from the SentinelOne Deep Visibility perspective — MITRE ATT&CK kill chain map, a Deep Visibility query catching web-server parent-child behavior, and a Star Custom Rule that produced 26 alarms over a 7-day simulation.
20.07.2026 · 8 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with CrowdStrike Falcon
A case study of the WordPress Core WP2Shell RCE chain on a CrowdStrike Falcon Linux environment — end-to-end RCE testing with the public PoC, Falcon's built-in webshell visibility (NewScriptWritten, PhpEvalString, LinWebshell), and five behavioral Custom IOA rules (INFNT-IOA-0001 through 0005) validated from Detect through Process Kill.
20.07.2026 · 15 min
Analysis ReportTrusted Process Abuse: Why Doesn't MDE See the Command Hidden Behind vmtoolsd?
The anatomy of an EDR blind spot on Microsoft Defender for Endpoint: why the PowerShell command spawned under vmtoolsd via vSphere Guest Operations doesn't raise an alarm in DeviceProcessEvents, and how to close the gap with an Advanced Hunting query and a Custom Detection Rule.
03.07.2026 · 7 min
Analysis ReportCheck Point Harmony Endpoint — Trusted Process, the EDR Blind Spot: The VMware vmtoolsd Case
Why does Check Point Harmony stay silent on commands arriving via vSphere Guest Operations? Closing the gap step by step with a Threat Hunting query, a Behavioral Protection Custom Rule, and a 30-day backtest window.
03.07.2026 · 6 min
Analysis ReportThe Dark Side of the Hypervisor: EDR/XDR Bypass via VMware Guest Operations — A FortiEDR Case Study
An analysis of VMware Guest Operations abuse via the signed vmtoolsd process on FortiEDR — why the Trusted Parent design leaves this vector silent, how to catch it with a Threat Hunting query turned into a Custom Rule, and Defense-in-Depth recommendations.
03.07.2026 · 6 min
Analysis ReportTrusted Process Abuse: The EDR Blind Spot — A Cortex XDR Case Study on VMware Tools (vmtoolsd)
An analysis of Guest Operations abuse via the signed and trusted vmtoolsd with Palo Alto Cortex XDR — a CGO-based XQL query, a BIOC rule that persists the detection, and a Restrictions (Custom Prevention) profile configuration for real-time blocking.
03.07.2026 · 9 min
Analysis ReportTrusted Process: Detecting VMware Guest Operations Abuse with CrowdStrike Falcon
Detecting Guest Operations abuse via the signed and trusted vmtoolsd.exe with CrowdStrike Falcon — endpoint telemetry, Advanced Event Search / LogScale hunting query, a recommended Custom IOA rule, and tuning steps.
03.07.2026 · 7 min
Analysis ReportSentinelone — Trusted Process Abuse: The EDR Blind Spot — VMware Tools (vmtoolsd)
How can signed and trusted processes bypass EDR behavioral detection? Analysis of Guest Operations abuse via VMware Tools' vmtoolsd component using SentinelOne DeepVisibility, plus a custom detection rule.
03.07.2026 · 6 min
Analysis ReportCVE-2026-41651 — Pack2TheRoot: A Race Condition to Root via PackageKit
Pack2TheRoot vulnerability discovered in the default PackageKit service on Linux — three separate bugs (unconditional flag overwrite, silent state rejection, late flag read) combine so an ordinary user can install arbitrary packages as root. Technical analysis of the Time-of-Check / Time-of-Use race condition.
04.06.2026 · 9 min