When the hunter becomes the hunted: Using custom callbacks to disable EDRs
In the ever-evolving landscape of cybersecurity, the race between attackers and defenders is relentless. Security mechanisms, particularly those at the kernel level, are designed to provide robust protection against sophisticated threats. However, as attackers continuously devise new methods to bypass these defenses, the hunters—our trusted Endpoint Detection and Response (EDR) systems—can themselves become the hunted. This blog delves into a chilling demonstration of how a signed rootkit, can leverage the PsSetCreateProcessNotifyRoutine function to cripple EDR processes. By registering a custom callback, this rootkit effectively blindsides security defenses, preventing critical EDR processes from starting and leaving the system vulnerable to undetected malicious activities. Join us as we explore this advanced threat tactic, emphasizing the urgent need for fortified kernel-level protections to maintain the integrity and effectiveness of our security infrastructure. When a process, such
Intro In the ever-evolving landscape of cybersecurity, the race between attackers and defenders is relentless. Security mechanisms, particularly those at the kernel level, are designed to provide robust protection against sophisticated threats. However, as attackers continuously devise new methods to bypass these defenses, the hunters—our trusted Endpoint Detection and Response (EDR) systems—can themselves become the hunted. This blog delves into a chilling demonstration of how a signed rootkit, can leverage the PsSetCreateProcessNotifyRoutine function to cripple EDR processes. By registering
Explore this link on the map →related reading
- Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Mediummedium.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Detection: BCDEdit Failure Recovery Modification | Splunk Security Contentresearch.splunk.com
- Cloud Detection & Response: Simplifying Cloud Securityarmosec.io
- Why Endpoint Security Tools Are Still Such a Challengedatabreachtoday.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Report: The Era of Endpoints | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- What Is Identity Threat Detection & Response (ITDR)? | Proofpoint USproofpoint.com
- Mediumdetect.fyi
- Capability Abstraction - SpecterOpsposts.specterops.io
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org