Lessons learned from EDR Bypass threat hunting | by Cristóbal Martínez | Medium
A few months ago, I had to undertake a hunt about EDR bypass. This post includes some of the valuable lessons I learned as a Threat Hunter, when I could finally delve into this type of attacks, beyond the inherent fear that any defensive security technician usually has when such a task is mentioned. Before getting into the subject, it is necessary to know some important details, given that this hunt is not the typical hunt where one can follow the standard process for example, from The Hunter’s Framework (THF for friends). We are talking about EDR bypass... So, i was playing with one eye closed and hopping on one foot. Another day at the office for the average hunter. With this panorama, I began to study the existing techniques of EDR bypass, which led me to ask the first important question. What was I going to consider as an EDR bypass? The question is important because the shadow of tampering is there. This is my own definition: Any type of attack that allows to invisibilize a threat
Lessons learned from EDR Bypass threat hunting An important leassong that i learned after make an EDR bypass hunt Cristóbal Martínez 4 min read · Mar 24, 2024 -- Listen Share A few months ago, I had to undertake a hunt about EDR bypass . This post includes some of the valuable lessons I learned as a Threat Hunter, when I could finally delve into this type of attacks , beyond the inherent fear that any defensive security technician usually has when such a task is mentioned. Before getting into the subject, it is necessary to know some important details, given that this hunt is not the typical h
Explore this link on the map →saved by
related reading
- More on Threat Huntingtaosecurity.blogspot.com
- The dotted lines between Threat Hunting and Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- What Is Cyber Threat Hunting? Complete Guide | Exabeamexabeam.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Navigating the crossroads of Threat Hunting & Detection Engineering | by Alex Teixeira | Detect FYIdetect.fyi
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Introducing the PEAK Threat Hunting Framework | Splunksplunk.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- When the hunter becomes the hunted: Using custom callbacks to disable EDRsalteredsecurity.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com