ThreatPaper
Verified

Ivanti's Integrity Checker Tool is not sufficient to detect compromise

Assessment

CISA and seven partner agencies said so in AA24-060B on 29 February 2024, and the record supports it. Volexity found UTA0178 had altered the built-in checker to always report no findings even when mismatched files existed. Mandiant described the tool as a snapshot that cannot detect an actor who has restored the appliance to a clean state, and recommended the external checker because the internal one was being tampered with. Ivanti's own guidance still directed customers to run it.

Where this claim appeared

CISA · 2024-02-29

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Ivanti Connect Secure zero-days: one December intrusion, 2,100 backdoored appliances and a federal disconnect order

Think this assessment is wrong? Report an error.