Security News Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon

Parkinsond

Level 63
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,286
16,506
6,169
Windows defenders are facing a new way for attackers to hide activity after gaining administrator access.

The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk.

Rather than dropping a visible replacement file or modifying security software, an attacker can make a trusted path quietly return malicious content.

This creates a gap between what a process runs and what endpoint tools believe they are inspecting.