- What: GhostTree technique uses NTFS junctions to evade security scans
- Impact: Makes it harder for EDR tools to detect malicious files
Endpoint/Device Security GhostTree technique uses NTFS junctions to evade security scans June 16, 2026 Share By SC Staff A new technique dubbed GhostTree allows attackers to create recursive loops using NTFS junctions, making it impossible for security tools to scan directories, according to Varonis. This method exploits a feature that requires no special privileges to create, potentially leaving malicious files hidden and unexamined, with further coverage provided by Bleeping Computer. GhostTree leverages NTFS junctions, a file system feature that allows one directory to point to another. Attackers can create a junction that points back to its parent directory, forming a recursive loop. This loop generates an almost infinite number of valid file paths, causing directory scanning tools, including endpoint detection and response (EDR) products like Windows Defender, to hang indefinitely. The technique, which requires only write access to a folder, allows malware placed in the parent directory to go undetected. While Microsoft initially closed a report on the issue, a patch was later released. This highlights the importance of monitoring file system activity beyond endpoint scanning, as anomalous junction creation can be a strong indicator of malicious intent. Source: Bleeping Computer SC Staff Related Endpoint/Device Security Microsoft Defender for Endpoint to automatically isolate compromised devices SC Staff May 26, 2026 The new feature automatically disconnects compromised endpoints from the network, limiting the risk of further impact while maintaining connectivity to the Defender for Endpoint service for continued monitoring. Endpoint/Device Security Windows 10 KB5087544 update fixes Remote Desktop warnings and Secure Boot reporting SC Staff May 13, 2026 The KB5087544 update for Windows 10, available for Enterprise LTSC and ESU program participants, primarily delivers security fixes and bug resolutions, addressing 120 vulnerabilities patched in May 2026. Security Operations Tanium and ServiceNow partner for autonomous IT operations SC Staff May 8, 2026 The collaboration merges Tanium's real-time endpoint intelligence with ServiceNow's workflow orchestration to address the gap between IT visibility and action. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Anti-Malware Antivirus Software Bring Your Own Device (BYOD) Ephemeral Port Extranet Endpoint Security Firmware Keylogger Registry You can skip this ad in 5 seconds