Detecting (Evil) Dylibs
MalwareAttackers are increasingly turning to dylibs to host malicious code, gain stealth, and inherit the trust of legitimate processes. In this blog post, we explore how to statically enumerate dylib dependencies, inspect libraries loaded into running processes, and leverage Endpoint Security to detect, and even block, malicious dylibs at load time.
Read full story at Objective-See →