In this installment of The Detection Series, we examine how installer packages work on different operating systems and analyze the ways in which adversaries are abusing them. We'll demonstrate how organizations can investigate the contents of installer packages and offer tips on how to defend against malicious installers.
We’re also joined by Cat Self from MITRE ATT&CK®. She is a macOS and Linux specialist there. Cat was previously a red teamer and also served in military intelligence.
For more details on MSIX, check out this blog: https://redcanary.com/blog/threat-int...
Follow Cat:
/ coolestcatiknow
Follow Frank:
/ cyb3rp4nd4
Follow us:
/ redcanary
/ redcanary
---
Red Canary stops cyber threats no one else does, so organizations can fearlessly pursue their missions. We do it by delivering managed detection and response (MDR) across enterprise endpoints, cloud workloads, network, identities, and SaaS apps. As a security ally, we define MDR in our own terms with unlimited 24×7 support, deep threat expertise, hands-on remediation, and by doing what’s right for customers and partners.
Subscribe to our YouTube channel for frequently updated, how-to content about Atomic Red Team, threat hunting in security operations, MDR or Managed Detection and Response, and using the MITRE ATT&CK® framework.