InfinitumIT

Blog

Latest insights from the threat landscape

Analysis Report

WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Microsoft Defender for Endpoint

A live lab test of the CVE-2026-63030 wp2shell chain against MDE for Linux: no configuration — including the strictest protection profile — produced an alert. Advanced Hunting queries (DeviceFileEvents + DeviceProcessEvents) turned into a Custom Detection Rule that catches the web-server → shell/discovery/download behavior.

21.07.2026 · 7 min

Analysis Report

WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Check Point Harmony Endpoint

The CVE-2026-63030 wp2shell vulnerability analyzed on Check Point Harmony Endpoint with InfinitumIT lab test findings: the default policy raised no alerts through STEP 1-4 of the attack chain. Five Custom Detection Rules deployable as filter-chip bookmarks in the CP XDR Threat Hunting page, plus one retrospective hunt query.

20.07.2026 · 14 min

Analysis Report

WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Cortex XDR

The CVE-2026-63030 wp2shell vulnerability disclosed on 17 July 2026 — a pre-auth RCE chaining route confusion with SQL injection on the WordPress REST API batch endpoint. Five BIOCs plus one retrospective hunt query deployable on Cortex XDR, with a validated Behavioral Threat Protection kernel-level inline block against the T1036.004 Masquerading step in the InfinitumIT lab.

20.07.2026 · 10 min

Analysis Report

WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with SentinelOne

An analysis of the WordPress Core CVE-2026-63030 WP2Shell vulnerability from the SentinelOne Deep Visibility perspective — MITRE ATT&CK kill chain map, a Deep Visibility query catching web-server parent-child behavior, and a Star Custom Rule that produced 26 alarms over a 7-day simulation.

20.07.2026 · 8 min

Analysis Report

WP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with CrowdStrike Falcon

A case study of the WordPress Core WP2Shell RCE chain on a CrowdStrike Falcon Linux environment — end-to-end RCE testing with the public PoC, Falcon's built-in webshell visibility (NewScriptWritten, PhpEvalString, LinWebshell), and five behavioral Custom IOA rules (INFNT-IOA-0001 through 0005) validated from Detect through Process Kill.

20.07.2026 · 15 min

Analysis Report

Trusted Process Abuse: Why Doesn't MDE See the Command Hidden Behind vmtoolsd?

The anatomy of an EDR blind spot on Microsoft Defender for Endpoint: why the PowerShell command spawned under vmtoolsd via vSphere Guest Operations doesn't raise an alarm in DeviceProcessEvents, and how to close the gap with an Advanced Hunting query and a Custom Detection Rule.

03.07.2026 · 7 min

Analysis Report

Check Point Harmony Endpoint — Trusted Process, the EDR Blind Spot: The VMware vmtoolsd Case

Why does Check Point Harmony stay silent on commands arriving via vSphere Guest Operations? Closing the gap step by step with a Threat Hunting query, a Behavioral Protection Custom Rule, and a 30-day backtest window.

03.07.2026 · 6 min

Analysis Report

The Dark Side of the Hypervisor: EDR/XDR Bypass via VMware Guest Operations — A FortiEDR Case Study

An analysis of VMware Guest Operations abuse via the signed vmtoolsd process on FortiEDR — why the Trusted Parent design leaves this vector silent, how to catch it with a Threat Hunting query turned into a Custom Rule, and Defense-in-Depth recommendations.

03.07.2026 · 6 min

Analysis Report

Trusted Process Abuse: The EDR Blind Spot — A Cortex XDR Case Study on VMware Tools (vmtoolsd)

An analysis of Guest Operations abuse via the signed and trusted vmtoolsd with Palo Alto Cortex XDR — a CGO-based XQL query, a BIOC rule that persists the detection, and a Restrictions (Custom Prevention) profile configuration for real-time blocking.

03.07.2026 · 9 min

Analysis Report

Trusted Process: Detecting VMware Guest Operations Abuse with CrowdStrike Falcon

Detecting Guest Operations abuse via the signed and trusted vmtoolsd.exe with CrowdStrike Falcon — endpoint telemetry, Advanced Event Search / LogScale hunting query, a recommended Custom IOA rule, and tuning steps.

03.07.2026 · 7 min

Analysis Report

Sentinelone — Trusted Process Abuse: The EDR Blind Spot — VMware Tools (vmtoolsd)

How can signed and trusted processes bypass EDR behavioral detection? Analysis of Guest Operations abuse via VMware Tools' vmtoolsd component using SentinelOne DeepVisibility, plus a custom detection rule.

03.07.2026 · 6 min

Analysis Report

CVE-2026-41651 — Pack2TheRoot: A Race Condition to Root via PackageKit

Pack2TheRoot vulnerability discovered in the default PackageKit service on Linux — three separate bugs (unconditional flag overwrite, silent state rejection, late flag read) combine so an ordinary user can install arbitrary packages as root. Technical analysis of the Time-of-Check / Time-of-Use race condition.

04.06.2026 · 9 min

Our team certifications

Experts accredited by SANS, Offensive Security, EC-Council, CompTIA, ISACA, CREST, and INE.

SANS GPEN
SANS GWAPT
SANS GICSP
SANS GRTP
SANS GCIH
SANS GSEC
Offensive Security OSCP
Offensive Security OSWP
EC-Council CEH
CompTIA Security+
ISACA CISM
ISACA CISA
CREST CRT
INE eWPTX
Fortinet FCP Secure Networking
Fortinet FCP Cloud Security
Fortinet FCP Security Operations
Fortinet FCSS Secure Networking
Fortinet FCSS SASE
Fortinet FCSS Cloud Security
Fortinet FCSS Security Operations
IBM QRadar Admin
SANS GPEN
SANS GWAPT
SANS GICSP
SANS GRTP
SANS GCIH
SANS GSEC
Offensive Security OSCP
Offensive Security OSWP
EC-Council CEH
CompTIA Security+
ISACA CISM
ISACA CISA
CREST CRT
INE eWPTX
Fortinet FCP Secure Networking
Fortinet FCP Cloud Security
Fortinet FCP Security Operations
Fortinet FCSS Secure Networking
Fortinet FCSS SASE
Fortinet FCSS Cloud Security
Fortinet FCSS Security Operations
IBM QRadar Admin

Cookie usage

We only use essential session and language preference cookies; no third-party tracking cookies. For details, see our Cookie Policy and KVKK Privacy Notice.