flâneur — a map of the web's best reading

Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Medium

medium.com · 1,087 words · saved by 1 readers

A few months ago, I had to undertake a hunt about EDR bypass. This post includes some of the valuable lessons I learned as a Threat Hunter, when I could finally delve into this type of attacks, beyond the inherent fear that any defensive security technician usually has when such a task is mentioned. Before getting into the subject, it is necessary to know some important details, given that this hunt is not the typical hunt where one can follow the standard process for example, from The Hunter’s Framework (THF for friends). We are talking about EDR bypass... So, i was playing with one eye closed and hopping on one foot. Another day at the office for the average hunter. With this panorama, I began to study the existing techniques of EDR bypass, which led me to ask the first important question. What was I going to consider as an EDR bypass? The question is important because the shadow of tampering is there. This is my own definition: Any type of attack that allows to invisibilize a threat

Lessons learned from EDR Bypass threat hunting An important leassong that i learned after make an EDR bypass hunt Cristóbal Martínez 4 min read · Mar 24, 2024 -- Listen Share A few months ago, I had to undertake a hunt about EDR bypass . This post includes some of the valuable lessons I learned as a Threat Hunter, when I could finally delve into this type of attacks , beyond the inherent fear that any defensive security technician usually has when such a task is mentioned. Before getting into the subject, it is necessary to know some important details, given that this hunt is not the typical h

Explore this link on the map →

saved by

related reading