
Gryxa Toolkit Collects Windows Logs to Learn How Defenders Tried to Remove It
The toolkit uses legitimate remote monitoring and management (RMM) software for covert access, maintains several recovery mechanisms, steals browser-stored credentials, and can retaliate by disabling endpoint security tools. Its most unusual feature appears after defenders remove the visible RMM implant A surviving component gathers Windows logs and host artifacts that could reveal how the response […]
The post Gryxa Toolkit Collects Windows Logs to Learn How Defenders Tried to Remove It appeared first on Cyber Security News.