frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Strengthening Microsoft Defender: Understanding Logical Evasion Threats

https://zenodo.org/records/15855685
2•vinhatson•9h ago

Comments

vinhatson•9h ago
In the high-stakes arena of cybersecurity, Microsoft Defender stands as a cornerstone of Windows security, integrating a sophisticated array of defenses: the Antimalware Scan In terface (AMSI) for runtime script scanning, Endpoint Detection and Response (EDR) for real-time telemetry, cloud-based reputation services for file analysis, sandboxing for iso lated execution, and machine learning-driven heuristics for behavioral detection. Despite its robust architecture, attackers increasingly bypass these defenses—not by exploiting code-level vulnerabilities within the Microsoft Security Response Center’s (MSRC) ser vice boundaries, but by targeting logical vulnerabilities in Defender’s decision-making and analysis pipelines. These logical attacks manipulate the system’s own rules, turning its complexity into a weapon against it. This article series, Strengthening Microsoft Defender: Analyzing and Countering Logi cal Evasion Techniques, is designed to empower Blue Teams, security researchers, threat hunters, and system administrators with the knowledge to understand, detect, and neu tralize these threats. By framing logical evasion techniques as threat models and providing actionable Indicators of Compromise (IoCs) and defensive strategies, we aim to bridge the gap between attacker ingenuity and defender resilience. Our approach is grounded in ethical research, responsible disclosure, and practical application, ensuring that defenders can anticipate and counter sophisticated attacks without crossing legal or ethical lines.
reify•5h ago
A jolly good reason to install Linux

I sometimes thank my lucky stars that for 20 years I have not had to run any anti-virus software or anti-malware programs, whether microsoft or third party, and wait for an eternity for them to finish.

not to mention windows update taking another eternity.

Nor piss about with windows firewall and defender.

I just wanted to freely surf the internet unburdened by the bloat that all windows has become.

I have tried every possible variety of distro over 20 years and they have all provided a road to freedom and sanity.

just look at that list below.

Ask HN: Why isn't mobile phone service restricted to emergency numbers only?

1•amichail•49s ago•0 comments

Using Large Language Models to Infer Problematic Instagram Use

https://www.mdpi.com/2079-9292/14/13/2548
1•PaulHoule•3m ago•0 comments

EU Floats Dynamic Price Cap on Russian Oil Under Market Pressure

https://oilprice.com/Latest-Energy-News/World-News/EU-Floats-Dynamic-Price-Cap-on-Russian-Oil-Under-Market-Pressure.html
1•Bluestein•3m ago•0 comments

Robinhood's Crypto Trading Promotions Probed by Florida AG

https://www.bloomberg.com/news/articles/2025-07-10/robinhood-s-crypto-trading-promotions-probed-by-florida-ag
1•Bluestein•5m ago•0 comments

Italy's Mosaic School

https://www.bbc.com/travel/article/20250707-inside-italys-secret-mosaic-school
1•andsoitis•9m ago•0 comments

A Doctor Said Israel's War Is Fueling Health Crises in Gaza. UCSF Fired Her

https://theintercept.com/2025/06/05/gaza-israel-san-francisco-ucsf-doctor-professor/
6•heavyset_go•11m ago•0 comments

Claude now connects with Canvas, Panopto, and Wiley for educational access

https://the-decoder.com/claude-now-connects-with-canvas-panopto-and-wiley-for-educational-access/
1•alwillis•11m ago•0 comments

Open Source Tools to Detect CVE-2024-54085

https://eclypsium.com/blog/eclypsium-releases-tools-for-detecting-ami-megarac-bmc-vulnerabilities/
1•cws•11m ago•0 comments

Show HN: Highlight Text to Send Directly into ChatGPT

https://chromewebstore.google.com/detail/chatgpt-search-use-on-any/ekamciedckbbigpojmkhbaoddfbdkphi
1•bluelegacy•14m ago•0 comments

Color Block Jam Level Guide

https://www.colorblockjamlevel.app/
1•cnych•18m ago•0 comments

Extending Self-Discharge Time of Dicke Quantum Batteries with Molecular Triplets

https://journals.aps.org/prxenergy/abstract/10.1103/bhyh-53np
1•gnabgib•18m ago•0 comments

Advice, like youth, probably just wasted on the young (1997)

https://www.chicagotribune.com/news/columnists/chi-schmich-sunscreen-column,0,4054576.column
1•GeoAtreides•20m ago•0 comments

Peter Jackson-backed biotech company sets its "de-extinction" sights on NZ Moa

https://www.houstonchronicle.com/news/houston-texas/trending/article/moa-colossal-biosciences-20764414.php
1•WorkerBee28474•20m ago•1 comments

Perlan Project

https://en.wikipedia.org/wiki/Perlan_Project
1•ZeljkoS•21m ago•0 comments

A model for IV&V that's useful

https://waldo.jaquith.org/blog/2025/04/a-model-for-ivv-thats-actually-useful/
1•gregsadetsky•21m ago•0 comments

Learning to Learn (In the Age of LLMs)

https://www.carette.xyz/posts/learning_to_learn/
1•LucidLynx•21m ago•0 comments

Rattleback

https://en.wikipedia.org/wiki/Rattleback
2•pingohits•23m ago•0 comments

Is Telecom the New Tequila?

https://www.fastcompany.com/91349907/why-smartless-podcast-is-launching-its-own-wireless-brand
2•mooreds•26m ago•0 comments

Beyond CVE: Integrating Multiple Sources for Complete Vulnerability Intelligence

https://guptadeepak.com/beyond-cve-building-a-complete-vulnerability-intelligence-strategy/
1•guptadeepak•28m ago•1 comments

Linda Yaccarino Resigns as 'CEO' of X

https://twitter.com/lindayaX/status/1942957094811951197
1•Bogdanp•29m ago•2 comments

Show HN: Bullpost about founders and startups to show your conviction

https://rova.xyz/
1•spenserhuang•29m ago•0 comments

Symbiosis as Metaphor

https://laurabrekelmans.substack.com/p/symbiosis-as-metaphor-part-1
1•azeirah•30m ago•0 comments

Show HN: Bedrock – An 8-bit computing system for running programs anywhere

https://benbridle.com/projects/bedrock.html
1•benbridle•31m ago•0 comments

Anyone's Steam Just Die?

https://old.reddit.com/r/Steam/comments/1lwprz4/anyones_steam_just_die/
4•MonkeyClub•35m ago•9 comments

Show HN: Scribble Draw (Image Generation)

https://www.scribbledraw.com/
1•jchiu1234•38m ago•0 comments

Trump to use presidential authority to send weapons to Ukraine, sources say

https://www.reuters.com/world/europe/trump-use-presidential-authority-send-weapons-ukraine-sources-say-2025-07-10/
3•MilnerRoute•40m ago•4 comments

Use LLMs over DNS at Ch.at

https://github.com/Deep-ai-inc/ch.at
2•xenoduck•42m ago•0 comments

An open letter from educators who refuse the call to adopt GenAI in education

https://openletter.earth/an-open-letter-from-educators-who-refuse-the-call-to-adopt-genai-in-education-cb4aee75
17•mathgenius•42m ago•10 comments

Energy and AI Observatory

https://www.iea.org/data-and-statistics/data-tools/energy-and-ai-observatory
1•gmays•42m ago•0 comments

Establishing First-Time Security Functions in FAANG [video]

https://www.youtube.com/watch?v=wseqtJDDhNs
1•wslh•43m ago•0 comments