Map cross-domain privilege escalation to sever breach routes at key choke points. SpecterOps said defenders can look for signs of process injection targeting chrome.exe and msedge.exe using Sysmon Event IDs 8 and 10. “Our analysis confirms that the investigated malware is a new CoolClient variant … Kaspersky has also published file hashes, paths, and C2 […]
