[HN Gopher] An unexpected journey into Microsoft Defender's sign...
       ___________________________________________________________________
        
       An unexpected journey into Microsoft Defender's signature World
        
       Author : serhack_
       Score  : 159 points
       Date   : 2024-06-30 08:38 UTC (2 days ago)
        
 (HTM) web link (retooling.io)
 (TXT) w3m dump (retooling.io)
        
       | Angostura wrote:
       | A note to the author: if you are going to include " EDR and EPP"
       | in the intro, please spell them out on first use
        
         | gpvos wrote:
         | EDR = Endpoint Detection and Response, EPP = Endpoint
         | Protection Platform. The main difference, I gather from
         | Wikipedia, is that EDR mainly alerts, and EPP actually stops
         | the attack.
        
           | kemotep wrote:
           | I have never heard of EPP but the premium version of
           | Microsoft Defender and things like SentinelOne bill
           | themselves as EDR and do in fact have response features to be
           | able to delete the virus files or disable network access of
           | the compromised device, kill running services, etc.
           | 
           | The R stands for Response.
        
             | technion wrote:
             | Marketing for both of these companies now claims edr is
             | obsolete and calls out the risk of using an edr product,
             | with xdr being the cool acronym of the month to sell.
        
           | qual wrote:
           | More precisely, EDR (somtimes EDTR -- endpoint detection and
           | threat response) is _one component_ of a robust endpoint
           | protection platform.
           | 
           | EPPs will consist of threat detection and response (EDR), as
           | well as proactive prevention, vulnerability management,
           | threat intelligence, data-loss prevention, encryption
           | management, etc.
        
         | USiBqidmOOkAqRb wrote:
         | Alternatively, <abbr> is a thing.
         | 
         | https://html.spec.whatwg.org/multipage/text-level-semantics....
        
         | serhack_ wrote:
         | I'm not the author, but I'll try to let them know :- )
        
       | FrostKiwi wrote:
       | Great deep dive! Always wondered about the details around this
       | topic.
       | 
       | Did a bit of red teaming around the topic of reverse shells and
       | privilege escalation and was pleasantly surprised, how much
       | Windows Defender catches. Our IT Department recently switched
       | away from a paid McAfee service doing end point security, which
       | failed to detect unauthorized access in many instances.
       | 
       | Also, I totally read the intro as "addressing the ERP use-case"
        
         | zelon88 wrote:
         | McAfee sold it's Entrerprise division in 2021. Ever since they
         | have primarily focused on scaring boomers into subscription
         | plans. They used to have an on-prem EDR platform called McAfee
         | EPO but I think that was replaced with some cloud hosted
         | subscription garbage. I won't use cloud based security
         | products. On-prem security should have an on-prem solution.
         | Anyone who says otherwise gets their paycheck by hawking
         | servitization or hosting data. The reasons for outsourcing are
         | weak.
         | 
         | To your point about reverse shells, last time I tried about 2
         | years ago, meterpreter was still sneaking past almost
         | everything. There are some tools on Github for detecting it,
         | but it is very good at evading detection in general.
        
           | lucasRW wrote:
           | Highly doubt that... to be certain about dates as these
           | things move fast, I refer to the OSEP course from Offensive
           | Security, which is mostly about evasion. Course released in
           | 2021, and which became necessary after the infamous OSCP,
           | since most payloads became detected by antivirus, which is
           | basically the starting point of that course: a default MSF
           | payload, even with various encoding, will trigger 50% or more
           | of AVs on virustotal.
        
             | zelon88 wrote:
             | So you describe a 50% failure rate and you doubt me? I
             | believe you have a false sense of confidence in your
             | suppliers and their products. Have fun rebuilding your
             | house of cards over and over again. Being dismissive about
             | security is the lowest hanging fruit there is.
        
               | lucasRW wrote:
               | I describe 50% of AV products detecting something you
               | said was "sneaking past almost everything".
        
           | gradyfps wrote:
           | McAfee ePO is the product that became Trellix ePO after
           | McAfee Enterprise was sold off.
        
         | dspillett wrote:
         | _> which failed to detect unauthorized access in many
         | instances._
         | 
         | Did something else detect them in a timely manner, or did you
         | find evidence later as part of some sort of audit?
         | 
         | (or was the inadequacy found via staged penetration testing?)
        
         | Cthulhu_ wrote:
         | ERP being "erotic roleplay"?
        
       | InDubioProRubio wrote:
       | Thaught it would mention at least the slow-down bug, that slows
       | some systems to a crawl as soon as defender scans some folders.
        
       | banish-m4 wrote:
       | MDE plan 2 had problems where MS was pushing out under-tested
       | signatures. One time, they pushed out defs that deleted all menu
       | shortcuts for some users, leading them to believe all of their
       | software had been uninstalled.
        
       ___________________________________________________________________
       (page generated 2024-07-02 23:01 UTC)