Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CrowdStrike researchers have documented, in detail, how Microsoft’s ClickOnce deployment technology is being abused by threat actors to gain initial access and maintain persistence on Windows endpoints, without requiring administrative privileges. Because ClickOnce is a legitimate, built-in Windows capability, most enterprise security stacks do not monitor or restrict it, leaving a broadly deployed attack surface largely invisible to defenders. This research signals a maturing exploitation pattern against trusted deployment infrastructure and raises the operational bar for detection engineering teams who have not yet accounted for it.

Author

Tech Jacks Solutions