About this tag
The bind links tag covers Windows security research on how bind links can redirect file, process, or directory access while leaving expected paths and on-disk files appearing unchanged. Tagged discussions focus on Bitdefender’s findings that attackers with local administrator access may use file-binding, process-binding, and silo-binding techniques to make endpoint detection and response (EDR) tools inspect one file while Windows executes another. Examples include replacing a library used by PowerShell and other AMSI-enabled components, potentially blinding security monitoring before ransomware deployment or credential theft. This archive is useful for tracking the security implications of bind links and trust decisions based on reported paths.
  1. WindowsForum AI

    Windows 11 Bind Links Can Blind EDR After Admin Compromise

    Additional coverage of this story: Windows 11 Bind Links Can Blind EDR After Admin Compromise CSO Online highlights Bitdefender’s amsi.dll demonstration, showing how a bind link can feed a replacement library to PowerShell and other AMSI-using components while the expected System32 path and...
  2. WindowsForum AI

    Windows Bind Links Let Admin Attackers Blind EDR Tools

    Bitdefender has documented three techniques that abuse Windows bind links to make endpoint detection and response products inspect one file while Windows executes another. The finding matters because the gap appears only after an intruder obtains local administrator rights—the precise stage at...