[HN Gopher] An unexpected journey into Microsoft Defender's sign...
___________________________________________________________________
An unexpected journey into Microsoft Defender's signature World
Author : serhack_
Score : 159 points
Date : 2024-06-30 08:38 UTC (2 days ago)
(HTM) web link (retooling.io)
(TXT) w3m dump (retooling.io)
| Angostura wrote:
| A note to the author: if you are going to include " EDR and EPP"
| in the intro, please spell them out on first use
| gpvos wrote:
| EDR = Endpoint Detection and Response, EPP = Endpoint
| Protection Platform. The main difference, I gather from
| Wikipedia, is that EDR mainly alerts, and EPP actually stops
| the attack.
| kemotep wrote:
| I have never heard of EPP but the premium version of
| Microsoft Defender and things like SentinelOne bill
| themselves as EDR and do in fact have response features to be
| able to delete the virus files or disable network access of
| the compromised device, kill running services, etc.
|
| The R stands for Response.
| technion wrote:
| Marketing for both of these companies now claims edr is
| obsolete and calls out the risk of using an edr product,
| with xdr being the cool acronym of the month to sell.
| qual wrote:
| More precisely, EDR (somtimes EDTR -- endpoint detection and
| threat response) is _one component_ of a robust endpoint
| protection platform.
|
| EPPs will consist of threat detection and response (EDR), as
| well as proactive prevention, vulnerability management,
| threat intelligence, data-loss prevention, encryption
| management, etc.
| USiBqidmOOkAqRb wrote:
| Alternatively, <abbr> is a thing.
|
| https://html.spec.whatwg.org/multipage/text-level-semantics....
| serhack_ wrote:
| I'm not the author, but I'll try to let them know :- )
| FrostKiwi wrote:
| Great deep dive! Always wondered about the details around this
| topic.
|
| Did a bit of red teaming around the topic of reverse shells and
| privilege escalation and was pleasantly surprised, how much
| Windows Defender catches. Our IT Department recently switched
| away from a paid McAfee service doing end point security, which
| failed to detect unauthorized access in many instances.
|
| Also, I totally read the intro as "addressing the ERP use-case"
| zelon88 wrote:
| McAfee sold it's Entrerprise division in 2021. Ever since they
| have primarily focused on scaring boomers into subscription
| plans. They used to have an on-prem EDR platform called McAfee
| EPO but I think that was replaced with some cloud hosted
| subscription garbage. I won't use cloud based security
| products. On-prem security should have an on-prem solution.
| Anyone who says otherwise gets their paycheck by hawking
| servitization or hosting data. The reasons for outsourcing are
| weak.
|
| To your point about reverse shells, last time I tried about 2
| years ago, meterpreter was still sneaking past almost
| everything. There are some tools on Github for detecting it,
| but it is very good at evading detection in general.
| lucasRW wrote:
| Highly doubt that... to be certain about dates as these
| things move fast, I refer to the OSEP course from Offensive
| Security, which is mostly about evasion. Course released in
| 2021, and which became necessary after the infamous OSCP,
| since most payloads became detected by antivirus, which is
| basically the starting point of that course: a default MSF
| payload, even with various encoding, will trigger 50% or more
| of AVs on virustotal.
| zelon88 wrote:
| So you describe a 50% failure rate and you doubt me? I
| believe you have a false sense of confidence in your
| suppliers and their products. Have fun rebuilding your
| house of cards over and over again. Being dismissive about
| security is the lowest hanging fruit there is.
| lucasRW wrote:
| I describe 50% of AV products detecting something you
| said was "sneaking past almost everything".
| gradyfps wrote:
| McAfee ePO is the product that became Trellix ePO after
| McAfee Enterprise was sold off.
| dspillett wrote:
| _> which failed to detect unauthorized access in many
| instances._
|
| Did something else detect them in a timely manner, or did you
| find evidence later as part of some sort of audit?
|
| (or was the inadequacy found via staged penetration testing?)
| Cthulhu_ wrote:
| ERP being "erotic roleplay"?
| InDubioProRubio wrote:
| Thaught it would mention at least the slow-down bug, that slows
| some systems to a crawl as soon as defender scans some folders.
| banish-m4 wrote:
| MDE plan 2 had problems where MS was pushing out under-tested
| signatures. One time, they pushed out defs that deleted all menu
| shortcuts for some users, leading them to believe all of their
| software had been uninstalled.
___________________________________________________________________
(page generated 2024-07-02 23:01 UTC)