Skip to content

Comment on Carbon Black S-1parent

Comments

Not at all, zero days are of course found in trusted code. But they are used to inject malware (file based). That malware is not on the trust list and therefore is blocked from executing.

For example - what turned out to be a zero day exploit was blocked from executing as it was an unknown app. It was an uninstall script that tried to run ever hour and appeared to be part of an AV solution.

9 months later, it was identified as a zero day exploit by 'traditional' AV companies.

Similarly it has blocked SHA1 attacks where for example a previously trusted app has been compromised but even if the SHA1 matches, the other 5 hashes don't and therefore it is not allowed to execute. If any one hash doesn't match - it is blocked.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.