Cisco be careful when using PowerShell

PowerShell was the source of more than a third of the critical security vulnerabilities identified in the second half of 2020, according to a Cisco survey released today at an RSA conference.

powershell

The top class of threats detected across Cisco Endpoint was dual-use used for exploitation work but also after exploitation.

PowerShell Empire, Cobalt , PowerSploit, and other similar tools have legitimate uses, Cisco says in its research, but they have also become common tools used by attackers. Such practices are used to avoid detection when running foreign tools or code to compromise systems.

"According to Cisco Research, PowerShell is the source of more than a third of critical threats," says Gedeon Hombrebueno, Cisco Secure Endpoint Security Product Manager.

Cisco offers some protection steps that, of course, are facilitated by Cisco Secure Endpoint, but also some other EDR tools (from endpoint detection and response).

Ωστόσο, υπάρχουν ορισμένα βήματα που οι διαχειριστές μπορούν (και πρέπει) να κάνουν εντελώς δωρεάν, όπως η πρόληψη ή ο περιορισμός της εκτέλεσης του PowerShell σε λογαριασμούς εκτός του διαχειριστή, επιτρέποντας την εκτέλεση μόνο υπογεγραμμένων script και τη χρήση της λειτουργίας Constrained .

You can read detailed instructions for protecting PowerShell in the following white paper or try it PowerShell Protect

Intel Insights: How to Secure PowerShell

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.
cisco, powershell

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).