Saturday 13 June 2026 01:30:05 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#EDR evasion


Windows QoS Turns Into an EDR Blind Spot

Published: 08 June 2026 08:02Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A newly disclosed red-team tool shows how a built-in policy feature can be repurposed to interfere with endpoint security visibility, without touching the usual tampering points.

A Ransomware Brand With Old Habits and New Evasion Tricks

Published: 04 June 2026 10:26Category: Ransomware & ExtortionAuthor: LOGICFALCON

Payouts King is being described as a post-BlackBasta threat that pairs social engineering overlap with code designed to frustrate some endpoint defenses.

AI Tools Enter the Post-Exploitation Workshop, and Active Directory Is the Prize

Published: 03 June 2026 15:00Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A June 2 intrusion analysis points to AI-assisted tooling being used to speed up Active Directory work and test endpoint defenses, without proving a full breach on its own.

Inside the Windows Hideout: How a Strange Endpoint Alert Led to AI-Labeled AD Recon

Published: 03 June 2026 14:14Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A suspicious path under a user profile, a post-exploitation toolkit, and claims of AI-assisted automation point to a quieter but dangerous shift: faster identity mapping and more deliberate EDR pressure.

When a Windows Shortcut Becomes a Scanner Trap

Published: 22 May 2026 17:49Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A junction-based traversal trick shows how ordinary NTFS features can turn recursive endpoint inspection into a reliability problem.

When a ZIP File Becomes the Delivery Room for a Stealer

Published: 12 May 2026 17:25Category: Malware & BotnetsAuthor: SIGNALMONK

A reported Vidar campaign shows how staged loaders, trusted utilities, and heavy obfuscation can narrow EDR visibility long enough for credential theft to happen.