# Is Elastic Endpoint immune to Zombie ZIP evasion?

**URL:** <https://discuss.elastic.co/t/is-elastic-endpoint-immune-to-zombie-zip-evasion/385438>\
**Category:** Elastic Security\
**Created:** [March 13, 2026, 1:44am UTC](https://discuss.elastic.co/t/is-elastic-endpoint-immune-to-zombie-zip-evasion/385438 "2026-03-13T01:44:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kenny-Yeh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenny-yeh/32/147121_2.png) [@Kenny-Yeh](https://discuss.elastic.co/u/Kenny-Yeh)\
**Post date:** [March 13, 2026, 1:44am UTC](https://discuss.elastic.co/t/is-elastic-endpoint-immune-to-zombie-zip-evasion/385438/1 "2026-03-13T01:44:17Z")

</div>

“Zombie ZIP“ is a newly disclosed malware evasion technique where attackers manipulate ZIP archive headers to bypass antivirus and EDR scanning. Based on the test by the researcher, it works against most AV engines on VirusTotal.

I would like to know whether Elastic endpoint is immune to this?

> **[GitHub - Bombadil-Systems/zombie-zip: Malformed ZIP archive that evades antivirus...](https://github.com/bombadil-systems/zombie-zip)**
>
> Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [March 16, 2026, 9:55am UTC](https://discuss.elastic.co/t/is-elastic-endpoint-immune-to-zombie-zip-evasion/385438/2 "2026-03-16T09:55:35Z")

</div>

Elastic Endpoint is EDR product, the malicious binary payload should be detected upon execution. This is similar to “scan files upon modification” option, where you can opt-out from it to improve performance but you still have guarantee that a malicious executable at rest won’t be allowed to execute.
