Silly EDR Bypasses and Where To Find Them
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Marcus Hutchins explores two novel techniques to bypass EDR (Endpoint Detection and Response) user-mode hooks without triggering callstack-based detections. The first method uses hardware breakpoints placed on the syscall and return instructions of hooked Nt functions, allowing an exception handler to swap benign parameters for
Sort: