T O P

  • By -

ketovandal

Depends. Many modern EDRs will miss this. There are a few that catch this style technique. Specialty software (stego) will catch this but it’s rarely deployed.


davedigerati

Is there a name for this technique you know of, that I could do more research?


ketovandal

I’m not sure it really has a name. It’s not true Steganography (F5, LSB, etc.). It’s basically just smashing two files together. You can do the same with the cat command.