Back to Resources

WSL: How Linux Ransomware Bypass AV on a Windows Device (unless SentinelOne is installed)

WSL (Windows Subsystem for Linux) lets administrators run Linux environments and command-line tools directly on Windows machines without the need to use virtualization platforms. WSL also opens a new attack surface and enables AV bypass by skipping Windows user mode hooks. This video demonstrates how SentinelOne agent detects an abuse of the WSL architecture – an open source ransomware named GonnaCry encrypts files at C: drive user’s folder and immediately detected. Visit https://www.sentinelone.com/

-~-

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.