Tracking a stolen code-signing certificate with osquery
blog.trailofbits.com | blog | #supply-chain | #incident-response | #malware | #threat-hunting | #windows | #supply-chain-attack | #code-signing | #osquery | #authenticode | #ccleaner
Summary
Using osquery's new Windows Authenticode checks, Trail of Bits shows how to hunt binaries signed with the stolen certificate in the CCleaner supply chain attack that hit 2.27 million machines.
- Published
- Collected
Skip to content