惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园 - 叶小钗
Stack Overflow Blog
Stack Overflow Blog
S
SegmentFault 最新的问题
D
DataBreaches.Net
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Threatpost
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
Jina AI
Jina AI
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
C
Cisco Blogs
PCI Perspectives
PCI Perspectives
Project Zero
Project Zero
G
Google Developers Blog
宝玉的分享
宝玉的分享
H
Heimdal Security Blog
美团技术团队
Schneier on Security
Schneier on Security
C
CERT Recently Published Vulnerability Notes
Martin Fowler
Martin Fowler
博客园 - 司徒正美
博客园 - 三生石上(FineUI控件)
Help Net Security
Help Net Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
C
Check Point Blog
Hacker News: Ask HN
Hacker News: Ask HN
L
LINUX DO - 最新话题
O
OpenAI News
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
Netflix TechBlog - Medium
S
Security Affairs
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
Blog — PlanetScale
Blog — PlanetScale
V
V2EX - 技术
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
F
Fortinet All Blogs
G
GRAHAM CLULEY
云风的 BLOG
云风的 BLOG
S
Secure Thoughts

Fortinet All Blogs

Advancing Threat-Informed Defense through Fortinet’s Collaboration with MITRE CTID | Fortinet Threat Actors Weaponize AI Hype to Deliver AsyncRAT | FortiGuard Labs Fortinet Achieves 1 Million People Trained in Cybersecurity Goal Ahead of Schedule | Fortinet Blog While OT Security Is Maturing, Risk Is Not Slowing Down | Fortinet Blog AI Policy Meets Operational Reality: White House AI Cybersecurity Order Calls for Public-Private Coordination | Fortinet Blog Executive Q&A: Strong Q1 Momentum Driven by Differentiated Innovation and Customer Demand | Fortinet Fortinet Earns AV-Comparatives Certification for EDR Detection Visibility | Fortinet Blog Cybercriminals Are Targeting the FIFA World Cup 2026 | FortiGuard Labs Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO | FortiGuard Labs Battling AI-Based Threats with FortiNDR | Fortinet Blog Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data Defending Critical Infrastructure: Why OT Security Demands a Threat-Informed Approach | CISO Collective Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise | FortiGuard Labs Fortinet Expands Cybersecurity Investment in the United Arab Emirates | Fortinet Blog PureLogs: Delivery via PawsRunner Steganography | FortiGuard Labs The Future of Connectivity | Fortinet Blog Fortinet at the World Economic Forum: Frontier AI models, AI-Driven Threats, Deepfakes, and the Future of Cyber Defense | Fortinet Blog The Fortinet 2025 Sustainability Report | Fortinet Blog Supercharged Security: Security in the Time of Mythos | CISO Collective Tracking Mirai Variant Nexcorium: A Vulnerability-Driven IoT Botnet Campaign | FortiGuard Labs AI Security Is an Architectural Decision | Fortinet Blog Fortinet Training Institute Wins Industry Accolades | Fortinet Blog Shadow AI: The Invisible Risk Growing Inside Your Organization | Fortinet Blog Leading by Example in Sustainability: Fortinet Expands Global EPD Certification | Fortinet Blog When Cybercrime Becomes an Industry | Fortinet Blog FortiOS 8.0: Redefining Secure Networking in the AI and Quantum Era | Fortinet Blog Securing the Physical World as It Comes Online | Fortinet Blog Why the 2026 AI Cybersecurity Summit Matters | Fortinet Blog DPRK-Related Campaigns with LNK and GitHub C2 | FortiGuard Labs AI Is Changing Application Threats Faster Than Teams Can Adapt | Fortinet Blog Announcing the Fortinet Training Institute’s 2026 ATC Award Winners | Fortinet Blog Disrupting Cybercrime Networks at Scale Requires Sustained Global Collaboration | Fortinet Blog
Fortinet Achieves AV-Comparatives Certification for Process Injection Protection | Fortinet Blog
Ankit Gupta · 2026-06-04 · via Fortinet All Blogs

Fortinet is proud to announce that FortiEDR has achieved certification in the AV-Comparatives 2026 Shellcode Execution/Process Injection Certification Test. Notably, all endpoint detection and response (EDR) capabilities evaluated in this assessment are also fully delivered through FortiEndpoint, Fortinet’s unified endpoint platform.

Fortinet successfully prevented or detected all 15 shellcode execution and process injection techniques evaluated in the assessment, achieving a 100% protection rate and passing the false-positive validation tests. This significantly exceeded AV-Comparatives’ certification requirement to prevent or detect at least 10 of 15 tested techniques without blocking legitimate applications.

The AV-Comparatives Process Injection Certification evaluates how effectively endpoint security solutions prevent or detect advanced shellcode execution and process injection techniques that attackers and red teams frequently use to evade traditional defenses. These techniques are commonly associated with ransomware, fileless malware, privilege escalation, credential theft, and lateral movement attacks.

Unlike traditional malware tests that focus primarily on file-based threats, this assessment specifically evaluates protection against evasive in-memory attack techniques mapped to MITRE ATT&CK T1055 (Process Injection).

By the Numbers

  • 15/15 process injection and shellcode execution techniques prevented or detected
  • 100% certification success rate
  • 0 false-positive failures
  • 50% higher coverage than the minimum certification requirement (15 tested vs. 10 required)
  • Protection validated against MITRE ATT&CK T1055 Process Injection techniques

Comprehensive Protection against Advanced Injection Techniques

To achieve certification, products were required to successfully prevent or detect at least two-thirds of the tested techniques without generating false positives for legitimate applications.

Fortinet successfully prevented or detected all 15 process injection and shellcode execution techniques tested in the assessment:

  1. Classic Remote Thread
  2. Thread Hijack
  3. Ghostwriting
  4. Transacted Hollowing
  5. Process Doppelganging
  6. APC Injection
  7. Early Bird APC
  8. Module Stomping
  9. Process Hollowing
  10. Process Herpaderping
  11. Dirty Vanity (Process Reflection Injection)
  12. Pool Party (Worker)
  13. TLS Callback
  14. Threadless Injection
  15. Fiber Injection

In addition, Fortinet passed the false-positive validation test, ensuring that legitimate applications were not improperly blocked or disrupted.

According to AV-Comparatives, Fortinet FortiEDR met the certification requirements by “successfully prevent[ing] or detect[ing] the Shellcode Execution/Process Injection attempts used in this test.”

Why Process Injection Protection Matters

Process injection remains one of the most widely used techniques in modern cyberattacks because it enables adversaries to hide malicious activity within legitimate processes and evade traditional signature-based security controls.

These techniques are frequently leveraged by attackers for:

  • Defensive evasion
  • Privilege escalation
  • Initial access operations
  • Fileless malware execution
  • Credential theft and lateral movement

The AV-Comparatives test intentionally varied multiple attack parameters, including shellcode frameworks, execution methods, APIs, injection techniques, and target processes, to simulate realistic attacker behavior.

The evaluated techniques included both self-injection and remote injection scenarios, using a variety of execution methods commonly associated with advanced threat actors and modern ransomware campaigns.

Independent Validation of Prevention-First Security

The certification further validates Fortinet’s prevention-first approach to endpoint security. Modern attacks increasingly rely on stealthy in-memory techniques to bypass traditional antivirus and static detection methods. Organizations therefore require behavioral protection that detects malicious runtime activity before attackers can establish persistence or move laterally.

Fortinet’s layered endpoint protection combines behavioral detection, exploit prevention, anti-ransomware protection, and real-time response to help organizations stop advanced threats earlier in the attack chain.

Unified Endpoint Security with FortiEndpoint

Although the certification was conducted using FortiEDR, customers receive the same validated EDR capabilities through FortiEndpoint, Fortinet’s unified endpoint platform.

FortiEndpoint unifies EPP, EDR, ZTNA/VPN, DLP, vulnerability visibility, threat-hunting telemetry, and AI-assisted operations into a single platform that simplifies endpoint security and improves protection and visibility across hybrid environments.

This unified approach helps organizations reduce agent sprawl, simplify operations with a single agent and a single console, accelerate detection and response, and lower operational overhead and total cost of ownership.

Building on Continued Third-Party Validation

This latest AV-Comparatives certification further reinforces Fortinet’s commitment to unified endpoint protection and advanced threat prevention. As attackers continue to adopt increasingly evasive in-memory techniques, Fortinet remains focused on helping organizations reduce risk, improve visibility, and strengthen resilience through an integrated endpoint security platform.

Read the full AV-Comparatives 2026 EDR Process Injection Protection report to learn more about the evaluation methodology and Fortinet’s results.

Learn more about Fortinet’s FortiEDR and FortiEndpoint solutions.