Javascript must be enabled to continue!
Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework
View through CrossRef
Background:
Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11. However, there is a major shortcoming in this system to stop Advanced Persistent Threat (APT). These are government-financed groups that are funded to attack other government entities. Following the initial security breach, the hacked Windows device is used to access the rest of the network devices in order to transfer data to external storage (Exfiltration).
Methods:
In this work, we have tested the Microsoft Windows Security system using MITRE CALDERA and ATT&CK frameworks and explain how APT groups are able to bypass Windows Security.
Results:
In this study we used "54ndc47" agent through GoLang feature in MITRE CALDERA platform to test and bypass Microsoft Windows Security systems (MS Windows 10). Through it, we were able to bypass the Windows Security system and display entire files in the victim's device.
Conclusions:
In this paper, we have provided recommendations to Microsoft to improve their Windows Security tool through the use of Artificial intelligence (AI).
Title: Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework
Description:
Background:
Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11.
However, there is a major shortcoming in this system to stop Advanced Persistent Threat (APT).
These are government-financed groups that are funded to attack other government entities.
Following the initial security breach, the hacked Windows device is used to access the rest of the network devices in order to transfer data to external storage (Exfiltration).
Methods:
In this work, we have tested the Microsoft Windows Security system using MITRE CALDERA and ATT&CK frameworks and explain how APT groups are able to bypass Windows Security.
Results:
In this study we used "54ndc47" agent through GoLang feature in MITRE CALDERA platform to test and bypass Microsoft Windows Security systems (MS Windows 10).
Through it, we were able to bypass the Windows Security system and display entire files in the victim's device.
Conclusions:
In this paper, we have provided recommendations to Microsoft to improve their Windows Security tool through the use of Artificial intelligence (AI).
Related Results
Deformation around the Creede Caldera: A consequence of isostatic adjustment following Caldera Formation
Deformation around the Creede Caldera: A consequence of isostatic adjustment following Caldera Formation
The pattern of deformation around the Creede caldera (26.5 Ma), southwest Colorado, may provide clues to the physical mechanisms of caldera evolution, particularly resurgent doming...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
Caldera collapse thresholds correlate with magma chamber dimensions
Caldera collapse thresholds correlate with magma chamber dimensions
AbstractExplosive caldera-forming eruptions eject voluminous magma during the gravitational collapse of the roof of the magma chamber. Caldera collapse is known to occur by rapid d...
Downsag calderas, ring faults, caldera sizes, and incremental caldera growth
Downsag calderas, ring faults, caldera sizes, and incremental caldera growth
Not all calderas conform to the currently favored model, in which a cylindrical block subsides as in cauldrons of deeply eroded volcanoes. Some calderas are downsagged structures, ...
Generation of Pre-Caldera Qixiangzhan and Syn-Caldera Millennium Rhyolites from Changbaishan Volcano by Shallow Remelting: Evidence from Zircon Hf–O Isotopes
Generation of Pre-Caldera Qixiangzhan and Syn-Caldera Millennium Rhyolites from Changbaishan Volcano by Shallow Remelting: Evidence from Zircon Hf–O Isotopes
The Changbaishan volcano is well known for its major caldera-forming Millennium Eruption (ME) in 946 CE (Common Era). We report Hf–O isotopes of zircon grains from pre-caldera Qixi...
The Origin of Toba Caldera Aquifers Based on Hydrogeology and Hydrogeochemistry, Northern Sumatra, Indonesia
The Origin of Toba Caldera Aquifers Based on Hydrogeology and Hydrogeochemistry, Northern Sumatra, Indonesia
The Toba Caldera exhibits complex geological processes with unique lithological characteristics serving as aquifers. Groundwater in the Toba Caldera is the primary water source for...
Malware and Windows APIs: A Dangerous Duo
Malware and Windows APIs: A Dangerous Duo
This paper introduces its interaction with malware and Windows APIs (application programming interface). The first section describes malware and investigates various types such as ...
Aspects of the Tectono-magmatic Evolution of Late Mesozoic Silicic Magmatic Systems in Hong Kong
Aspects of the Tectono-magmatic Evolution of Late Mesozoic Silicic Magmatic Systems in Hong Kong
<p>Hong Kong represents a microcosm of the magmatic and tectonic processes that are related to formation of the Southeast China Magmatic Belt (SCMB, ~1,300 km long by 400 km ...

