Blog
Latest insights from the threat landscape
Blocking ScreenConnect Abuse with CrowdStrike Application Abuse Prevention
The ScreenConnect chain installed through VBScript in an Adobe-themed phishing campaign, tested in a real CrowdStrike Falcon environment. We compare the real-time Application Abuse Prevention intervention against the RMM client, the MaliciousMsiInstaller detection at the MSI stage, and the early blocking provided at the script stage by an InfinitumIT Custom IOA rule.
13.09.2026 · 11 min
Analysis ReportThe Record Is There, the Alarm Isn't: Why Does MDE Ignore Classic Process Injection (T1055) by Default?
A third EDR blind spot on Microsoft Defender for Endpoint: this time not the trusted-parent chain, but the behavioral noise of cross-process memory operations. A test in a real MDE environment, detection with Advanced Hunting, and findings validated in a large-scale enterprise environment.
04.08.2026 · 7 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Microsoft Defender for Endpoint
A live lab test of the CVE-2026-63030 wp2shell chain against MDE for Linux: no configuration — including the strictest protection profile — produced an alert. Advanced Hunting queries (DeviceFileEvents + DeviceProcessEvents) turned into a Custom Detection Rule that catches the web-server → shell/discovery/download behavior.
21.07.2026 · 7 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Check Point Harmony Endpoint
The CVE-2026-63030 wp2shell vulnerability analyzed on Check Point Harmony Endpoint with InfinitumIT lab test findings: the default policy raised no alerts through STEP 1-4 of the attack chain. Five Custom Detection Rules deployable as filter-chip bookmarks in the CP XDR Threat Hunting page, plus one retrospective hunt query.
20.07.2026 · 14 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with Cortex XDR
The CVE-2026-63030 wp2shell vulnerability disclosed on 17 July 2026 — a pre-auth RCE chaining route confusion with SQL injection on the WordPress REST API batch endpoint. Five BIOCs plus one retrospective hunt query deployable on Cortex XDR, with a validated Behavioral Threat Protection kernel-level inline block against the T1036.004 Masquerading step in the InfinitumIT lab.
20.07.2026 · 10 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with SentinelOne
An analysis of the WordPress Core CVE-2026-63030 WP2Shell vulnerability from the SentinelOne Deep Visibility perspective — MITRE ATT&CK kill chain map, a Deep Visibility query catching web-server parent-child behavior, and a Star Custom Rule that produced 26 alarms over a 7-day simulation.
20.07.2026 · 8 min
Analysis ReportWP2Shell (CVE-2026-63030): Behavioral Detection of the WordPress Core Pre-Auth RCE Chain with CrowdStrike Falcon
A case study of the WordPress Core WP2Shell RCE chain on a CrowdStrike Falcon Linux environment — end-to-end RCE testing with the public PoC, Falcon's built-in webshell visibility (NewScriptWritten, PhpEvalString, LinWebshell), and five behavioral Custom IOA rules (INFNT-IOA-0001 through 0005) validated from Detect through Process Kill.
20.07.2026 · 15 min
Analysis ReportTrusted Process Abuse: Why Doesn't MDE See the Command Hidden Behind vmtoolsd?
The anatomy of an EDR blind spot on Microsoft Defender for Endpoint: why the PowerShell command spawned under vmtoolsd via vSphere Guest Operations doesn't raise an alarm in DeviceProcessEvents, and how to close the gap with an Advanced Hunting query and a Custom Detection Rule.
03.07.2026 · 7 min
Analysis ReportCheck Point Harmony Endpoint — Trusted Process, the EDR Blind Spot: The VMware vmtoolsd Case
Why does Check Point Harmony stay silent on commands arriving via vSphere Guest Operations? Closing the gap step by step with a Threat Hunting query, a Behavioral Protection Custom Rule, and a 30-day backtest window.
03.07.2026 · 6 min
Analysis ReportThe Dark Side of the Hypervisor: EDR/XDR Bypass via VMware Guest Operations — A FortiEDR Case Study
An analysis of VMware Guest Operations abuse via the signed vmtoolsd process on FortiEDR — why the Trusted Parent design leaves this vector silent, how to catch it with a Threat Hunting query turned into a Custom Rule, and Defense-in-Depth recommendations.
03.07.2026 · 6 min
Analysis ReportTrusted Process Abuse: The EDR Blind Spot — A Cortex XDR Case Study on VMware Tools (vmtoolsd)
An analysis of Guest Operations abuse via the signed and trusted vmtoolsd with Palo Alto Cortex XDR — a CGO-based XQL query, a BIOC rule that persists the detection, and a Restrictions (Custom Prevention) profile configuration for real-time blocking.
03.07.2026 · 9 min
Analysis ReportTrusted Process: Detecting VMware Guest Operations Abuse with CrowdStrike Falcon
Detecting Guest Operations abuse via the signed and trusted vmtoolsd.exe with CrowdStrike Falcon — endpoint telemetry, Advanced Event Search / LogScale hunting query, a recommended Custom IOA rule, and tuning steps.
03.07.2026 · 7 min