[HN Gopher] A universal EDR bypass built in Windows 10
___________________________________________________________________
A universal EDR bypass built in Windows 10
Author : aa_is_op
Score : 40 points
Date : 2023-10-10 17:28 UTC (5 hours ago)
(HTM) web link (www.riskinsight-wavestone.com)
(TXT) w3m dump (www.riskinsight-wavestone.com)
| taspeotis wrote:
| > some of its features can be turned off by a process having the
| SeDebugPrivilege or SeTcbPrivilege privilege, which can be
| achieved by any elevated process.
|
| Isn't this being on the other side of the airtight hatchway?
| peddling-brink wrote:
| In an absolute sense, sure. But turning off EDR allows more
| actions to be taken in the dark.
| einpoklum wrote:
| > ... a way for... processes to disable the generation of some
| security events... This technique could be used to evade EDR
| software
|
| So, you can disable some event logging for your process in
| Windows. Wow, what a grand discovery.
|
| Note also the wide use of boldface in the article. That just
| screams professionalism, doesn't it?
| resfirestar wrote:
| The significant thing here is that the technique should interfere
| with data collected by all common EDR software, rather than
| requiring specific tailoring for each one like most EDR bypass
| tricks. I'm curious about why the API protections present in
| Windows 11 couldn't be brought to Windows 10.
|
| >Multiple pieces of evidence show that Microsoft is aware of the
| weakness, but is not changing the API behavior retroactively on
| Windows 10, likely due to retro-compatibility issues.
|
| If MS actually says that, it seems like a lame excuse.
| ShamelessC wrote:
| Okay I'll be the first to ask -
|
| What the hell is EDR software?
| breser wrote:
| Endpoint Detection and Response. Basically a new term for
| antivirus/antimalware but that reports back to defenders and
| helps them respond to malicious software that may be on the
| device.
| ok123456 wrote:
| so it's malware.
| karmakaze wrote:
| "antivirus/antimalware" has gotten such a bad rap that it
| needed a makeover: EDR
| MenhirMike wrote:
| "I'd rather have ED than EDR."
| milkshakes wrote:
| never worked in an environment with hard security
| requirements?
|
| tell me, if your responsibility was to prevent, identify,
| and respond to breaches, what policies and technologies
| would you utilise to achieve this goal?
| ok123456 wrote:
| SolarWinds.
|
| Oh wait! It keeps happening!
| MenhirMike wrote:
| Oh, I fully understand why it's needed, and I have
| experience working with EDR software - which is why I
| stand by my statement that I'd rather deal with ED than
| EDR because at least there's a remedy for the former :P
| Hikikomori wrote:
| Fire everyone.
| jabroni_salad wrote:
| The comments on this site are really something after
| having worked for an engineering corp that was actively
| targeted for industrial espionage. You guys really don't
| wanna monitor what processes on your boxes are doing?
| Hopefully your servers don't do anything of consequence
| lol.
| throwanem wrote:
| A declaration of reputational bankruptcy, but where's the
| concomitant effort to restructure the reputational debt
| that necessitated it?
| boston_clone wrote:
| no, it's that the capabilities have evolved far beyond
| traditional antivirus that it's simply inaccurate to
| describe it as such.
| forward1 wrote:
| The only difference between malware and security software
| is the intent of its author. Functionally they are
| equivalent however.
| omgtehlion wrote:
| Well, the intent is usually the same: extract money from
| user, either outright stealing, or scare them and get
| paid for "protection"
| atoav wrote:
| Well antivirus is also software that has to:
|
| - be in a priviledged position on the system
|
| - open up all kind of files for analysis without the
| user's interaction
|
| Now if you want a way to create a juicy target for
| malware authors and increase the attack surface of your
| system, this is one way to do it.
| marcodiego wrote:
| I partially agree with you after seen behaviors of some
| "security" software that really put the "intent of its
| author" in question.
| boston_clone wrote:
| what part of EDR software seems malicious to you?
| Lammy wrote:
| The malicious mindset is right in the name. It redefines
| my computer to exist only in context of another thing. My
| hardware is now an """endpoint""" and not a standalone
| system.
| gruez wrote:
| It's not something that you're going to install on
| personal machines. It's something that the CISO wants
| installed on company machines for compliance reasons. And
| before you claim that you don't want your activity
| monitored on the company laptop, the laptop belongs to
| the company. There's no expectation of privacy.
| m-p-3 wrote:
| Some EDR examples for those wondering
|
| * CrowdStrike
|
| * SentinelOne
|
| * Heimdal
| waihtis wrote:
| > new term
|
| friend, the current term is XDR (eXtended Detection and
| Response - although that was a year or two ago and might be
| old in the market by now!)
| resfirestar wrote:
| XDR is a marketing term for a service that bundles or
| aggregates EDR with other types of enterprise level
| security monitoring. The endpoint part is still called EDR.
| cryptonector wrote:
| Quick, change it again so I can't know what you're talking
| about!
| bigstrat2003 wrote:
| I'm glad you asked, because I was baffled myself when I
| couldn't find a definition in the article.
| RachelF wrote:
| Yes, in many ways it is not a well-written article for those
| outside the the field.
| ska wrote:
| Perhaps because it was not written for those outside a
| particular field?
| [deleted]
___________________________________________________________________
(page generated 2023-10-10 23:01 UTC)