The Live Terminal feature of Cortex XDR can be abused by attackers as a pre-installed, EDR-trusted C2 channel
Uncategorized
1
Posts
1
Posters
0
Views
-
The Live Terminal feature of Cortex XDR can be abused by attackers as a pre-installed, EDR-trusted C2 channel
Abusing Cortex XDR Live Terminal as a C2 - InfoGuard Labs
The Cortex XDR agent includes an incident response feature called "Live Terminal", which attackers can abuse as a C2.
InfoGuard Labs (labs.infoguard.ch)
-
R relay@relay.infosec.exchange shared this topic