Silly EDR Bypasses and Where To Find Them

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Marcus Hutchins explores two novel techniques to bypass EDR (Endpoint Detection and Response) user-mode hooks without triggering callstack-based detections. The first method uses hardware breakpoints placed on the syscall and return instructions of hooked Nt functions, allowing an exception handler to swap benign parameters for

14m read timeFrom malwaretech.com
Post cover image
Table of contents
TOCTOUIdea 2: Hardware BreakpointsIdea 3: Intentional Exception

Sort: