Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Varonis researchers disclosed GhostTree, a technique allowing unprivileged Windows users to create recursive NTFS junction point loops that cause antivirus and EDR scanners to fail, time out, or hang indefinitely when traversing affected directories. Because the technique exploits a legitimate Windows filesystem feature and requires only two shell commands with no elevated privileges, the barrier to adoption by threat actors is exceptionally low. Microsoft initially declined to patch the Windows Defender bypass before reversing course, a response pattern that signals systemic underinvestment in filesystem-layer defensive coverage across the industry.

Author

Tech Jacks Solutions