[HN Gopher] A universal EDR bypass built in Windows 10
       ___________________________________________________________________
        
       A universal EDR bypass built in Windows 10
        
       Author : aa_is_op
       Score  : 40 points
       Date   : 2023-10-10 17:28 UTC (5 hours ago)
        
 (HTM) web link (www.riskinsight-wavestone.com)
 (TXT) w3m dump (www.riskinsight-wavestone.com)
        
       | taspeotis wrote:
       | > some of its features can be turned off by a process having the
       | SeDebugPrivilege or SeTcbPrivilege privilege, which can be
       | achieved by any elevated process.
       | 
       | Isn't this being on the other side of the airtight hatchway?
        
         | peddling-brink wrote:
         | In an absolute sense, sure. But turning off EDR allows more
         | actions to be taken in the dark.
        
       | einpoklum wrote:
       | > ... a way for... processes to disable the generation of some
       | security events... This technique could be used to evade EDR
       | software
       | 
       | So, you can disable some event logging for your process in
       | Windows. Wow, what a grand discovery.
       | 
       | Note also the wide use of boldface in the article. That just
       | screams professionalism, doesn't it?
        
       | resfirestar wrote:
       | The significant thing here is that the technique should interfere
       | with data collected by all common EDR software, rather than
       | requiring specific tailoring for each one like most EDR bypass
       | tricks. I'm curious about why the API protections present in
       | Windows 11 couldn't be brought to Windows 10.
       | 
       | >Multiple pieces of evidence show that Microsoft is aware of the
       | weakness, but is not changing the API behavior retroactively on
       | Windows 10, likely due to retro-compatibility issues.
       | 
       | If MS actually says that, it seems like a lame excuse.
        
       | ShamelessC wrote:
       | Okay I'll be the first to ask -
       | 
       | What the hell is EDR software?
        
         | breser wrote:
         | Endpoint Detection and Response. Basically a new term for
         | antivirus/antimalware but that reports back to defenders and
         | helps them respond to malicious software that may be on the
         | device.
        
           | ok123456 wrote:
           | so it's malware.
        
             | karmakaze wrote:
             | "antivirus/antimalware" has gotten such a bad rap that it
             | needed a makeover: EDR
        
               | MenhirMike wrote:
               | "I'd rather have ED than EDR."
        
               | milkshakes wrote:
               | never worked in an environment with hard security
               | requirements?
               | 
               | tell me, if your responsibility was to prevent, identify,
               | and respond to breaches, what policies and technologies
               | would you utilise to achieve this goal?
        
               | ok123456 wrote:
               | SolarWinds.
               | 
               | Oh wait! It keeps happening!
        
               | MenhirMike wrote:
               | Oh, I fully understand why it's needed, and I have
               | experience working with EDR software - which is why I
               | stand by my statement that I'd rather deal with ED than
               | EDR because at least there's a remedy for the former :P
        
               | Hikikomori wrote:
               | Fire everyone.
        
               | jabroni_salad wrote:
               | The comments on this site are really something after
               | having worked for an engineering corp that was actively
               | targeted for industrial espionage. You guys really don't
               | wanna monitor what processes on your boxes are doing?
               | Hopefully your servers don't do anything of consequence
               | lol.
        
               | throwanem wrote:
               | A declaration of reputational bankruptcy, but where's the
               | concomitant effort to restructure the reputational debt
               | that necessitated it?
        
               | boston_clone wrote:
               | no, it's that the capabilities have evolved far beyond
               | traditional antivirus that it's simply inaccurate to
               | describe it as such.
        
             | forward1 wrote:
             | The only difference between malware and security software
             | is the intent of its author. Functionally they are
             | equivalent however.
        
               | omgtehlion wrote:
               | Well, the intent is usually the same: extract money from
               | user, either outright stealing, or scare them and get
               | paid for "protection"
        
               | atoav wrote:
               | Well antivirus is also software that has to:
               | 
               | - be in a priviledged position on the system
               | 
               | - open up all kind of files for analysis without the
               | user's interaction
               | 
               | Now if you want a way to create a juicy target for
               | malware authors and increase the attack surface of your
               | system, this is one way to do it.
        
               | marcodiego wrote:
               | I partially agree with you after seen behaviors of some
               | "security" software that really put the "intent of its
               | author" in question.
        
             | boston_clone wrote:
             | what part of EDR software seems malicious to you?
        
               | Lammy wrote:
               | The malicious mindset is right in the name. It redefines
               | my computer to exist only in context of another thing. My
               | hardware is now an """endpoint""" and not a standalone
               | system.
        
               | gruez wrote:
               | It's not something that you're going to install on
               | personal machines. It's something that the CISO wants
               | installed on company machines for compliance reasons. And
               | before you claim that you don't want your activity
               | monitored on the company laptop, the laptop belongs to
               | the company. There's no expectation of privacy.
        
           | m-p-3 wrote:
           | Some EDR examples for those wondering
           | 
           | * CrowdStrike
           | 
           | * SentinelOne
           | 
           | * Heimdal
        
           | waihtis wrote:
           | > new term
           | 
           | friend, the current term is XDR (eXtended Detection and
           | Response - although that was a year or two ago and might be
           | old in the market by now!)
        
             | resfirestar wrote:
             | XDR is a marketing term for a service that bundles or
             | aggregates EDR with other types of enterprise level
             | security monitoring. The endpoint part is still called EDR.
        
             | cryptonector wrote:
             | Quick, change it again so I can't know what you're talking
             | about!
        
         | bigstrat2003 wrote:
         | I'm glad you asked, because I was baffled myself when I
         | couldn't find a definition in the article.
        
           | RachelF wrote:
           | Yes, in many ways it is not a well-written article for those
           | outside the the field.
        
             | ska wrote:
             | Perhaps because it was not written for those outside a
             | particular field?
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2023-10-10 23:01 UTC)