Skip to content
Threat Feed

Tag

Antivirus

10 briefs RSS
high advisory

Bitdefender Internet and Total Security Vulnerability Allows Privilege Escalation

A local attacker can exploit a vulnerability in Bitdefender Internet Security and Bitdefender Total Security to elevate their privileges on the affected system.

Bitdefender Internet Security +1 privilege-escalation antivirus software-vulnerability
1t
high advisory

Detection of Web Shell via Antivirus Signature

This brief describes the detection of web shells by antivirus solutions, emphasizing the importance of investigating these alerts as they signify a compromised web server and potential post-exploitation activity by an attacker.

webshell antivirus detection persistence
1r 1t
critical advisory

Detection of Malicious Remote Access Tools by Antivirus

This brief details a Sigma rule designed to detect Antivirus alerts flagging various malicious Remote Access Tools (RATs) such as AgentTesla, AsyncRAT, and NanoCore, highlighting the critical need for investigation into the initial infection vector even when the AV blocks the threat.

remote-access-trojan rat antivirus detection malware windows
1r 1t
critical advisory

Antivirus - Ransomware Signature Detection

This brief describes a critical Sigma rule designed to detect highly relevant Antivirus alerts reporting known ransomware families, enabling detection engineers to ensure immediate investigation even when the malware has been blocked.

ransomware antivirus windows
1r 1t
critical advisory

Antivirus Alert for Password Dumper and Stealer Activity

This brief details the detection of highly relevant antivirus alerts indicating the presence of password dumpers and stealers on endpoints, emphasizing the critical need for investigation even if the malware is blocked, to prevent credential compromise and subsequent attacks.

credential-access password-stealer password-dumper antivirus endpoint
1r 4t
high advisory

Antivirus Alert for Hacktools or Attack Tools

This brief describes the detection of highly relevant antivirus alerts specifically flagging hacktools or other attack tools via distinct signatures, indicating the presence of offensive security utilities or malicious software on endpoints, which requires immediate investigation despite the AV's block action.

antivirus hacktool post-exploitation detection incident-response malware
1r 1t
critical advisory

Detection of Advanced Persistent Threat (APT) Malware Signatures in Antivirus Logs

This brief details a detection rule for critical antivirus alerts that report Advanced Persistent Threat (APT) malware signatures, enabling detection engineers to identify and investigate sophisticated threats that have reached endpoints.

detection antivirus apt malware endpoint
1r 1t
medium advisory

Avast Antivirus Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in Avast Antivirus and AVG Technologies Anti-Virus to escalate privileges on a Windows system.

Avast Antivirus +1 privilege-escalation antivirus windows
2r 1t
high advisory

Potential Disabling of Windows Defender Antivirus via Registry Modification

An attacker might attempt to disable Windows Defender Antivirus by modifying specific registry keys, potentially leading to a system vulnerable to malware and other threats.

Windows Defender Antivirus windowsdefender registry antivirus disable malware
2r 1t
high advisory

Windows Defender Antivirus Disabled via Registry Modification

Attackers modify Windows Defender registry settings to disable antivirus and antispyware protections, evading detection and maintaining persistence.

Windows Defender +3 defense-evasion registry-modification antivirus
2r 1t