Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft Sysmon now detects malware process tampering attempts

Microsoft has released Sysmon 13 with a new security feature that detects if a process has been tampered using process hollowing or process herpaderping techniques. This tactic allows the malware to execute, but in Task Manager, it appears as a standard Windows process running in the background. To enable the process tampering detection feature, administrators need to add the ‘ProcessTampering’ configuration option to a configuration file to the Sysinternals tool. When a process tampering is detected, SysMon will generate an ‘Event 25 – Process Tampering’ entry in Event Viewer.

Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-sysmon-now-detects-malware-process-tampering-attempts/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security