Cargando…
Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework
Background: Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11. However, there is a major shortcoming in this system to stop Advanced Persistent Threat (APT). These are government-financed groups that ar...
Autor principal: | |
---|---|
Formato: | Online Artículo Texto |
Lenguaje: | English |
Publicado: |
F1000 Research Limited
2022
|
Materias: | |
Acceso en línea: | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9525993/ https://www.ncbi.nlm.nih.gov/pubmed/36226041 http://dx.doi.org/10.12688/f1000research.109148.3 |
_version_ | 1784800781876068352 |
---|---|
author | Mohamed, Nachaat |
author_facet | Mohamed, Nachaat |
author_sort | Mohamed, Nachaat |
collection | PubMed |
description | Background: Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11. However, there is a major shortcoming in this system to stop Advanced Persistent Threat (APT). These are government-financed groups that are funded to attack other government entities. Following the initial security breach, the hacked Windows device is used to access the rest of the network devices in order to transfer data to external storage (Exfiltration). Methods: In this work, we have tested the Microsoft Windows Security system using MITRE CALDERA and ATT&CK frameworks and explain how APT groups are able to bypass Windows Security. Results: In this study we used "54ndc47" agent through GoLang feature in MITRE CALDERA platform to test and bypass Microsoft Windows Security systems (MS Windows 10). Through it, we were able to bypass the Windows Security system and display entire files in the victim's device. Conclusions: In this paper, we have provided recommendations to Microsoft to improve their Windows Security tool through the use of Artificial intelligence (AI). |
format | Online Article Text |
id | pubmed-9525993 |
institution | National Center for Biotechnology Information |
language | English |
publishDate | 2022 |
publisher | F1000 Research Limited |
record_format | MEDLINE/PubMed |
spelling | pubmed-95259932022-10-11 Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework Mohamed, Nachaat F1000Res Research Article Background: Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11. However, there is a major shortcoming in this system to stop Advanced Persistent Threat (APT). These are government-financed groups that are funded to attack other government entities. Following the initial security breach, the hacked Windows device is used to access the rest of the network devices in order to transfer data to external storage (Exfiltration). Methods: In this work, we have tested the Microsoft Windows Security system using MITRE CALDERA and ATT&CK frameworks and explain how APT groups are able to bypass Windows Security. Results: In this study we used "54ndc47" agent through GoLang feature in MITRE CALDERA platform to test and bypass Microsoft Windows Security systems (MS Windows 10). Through it, we were able to bypass the Windows Security system and display entire files in the victim's device. Conclusions: In this paper, we have provided recommendations to Microsoft to improve their Windows Security tool through the use of Artificial intelligence (AI). F1000 Research Limited 2022-09-29 /pmc/articles/PMC9525993/ /pubmed/36226041 http://dx.doi.org/10.12688/f1000research.109148.3 Text en Copyright: © 2022 Mohamed N https://creativecommons.org/licenses/by/4.0/This is an open access article distributed under the terms of the Creative Commons Attribution Licence, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited. |
spellingShingle | Research Article Mohamed, Nachaat Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title | Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title_full | Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title_fullStr | Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title_full_unstemmed | Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title_short | Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework |
title_sort | study of bypassing microsoft windows security using the mitre caldera framework |
topic | Research Article |
url | https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9525993/ https://www.ncbi.nlm.nih.gov/pubmed/36226041 http://dx.doi.org/10.12688/f1000research.109148.3 |
work_keys_str_mv | AT mohamednachaat studyofbypassingmicrosoftwindowssecurityusingthemitrecalderaframework |