malwaretech, (edited )

Christmas gift article :)

An Introduction to Bypassing User Mode EDR Hooks

https://malwaretech.com/2023/12/an-introduction-to-bypassing-user-mode-edr-hooks.html

HalvarFlake,
@HalvarFlake@mastodon.social avatar

@malwaretech wait. EDRs using Usermode hooks are still a thing? I thought Usermode hooks went out of style in 2002?

malwaretech,

@HalvarFlake They did, but EDRs didn't get the memo

HalvarFlake,
@HalvarFlake@mastodon.social avatar

@malwaretech can you name and shame? 🙂

Crowdstrike wouldn't, would they?

dave_aitel,

@HalvarFlake @malwaretech they basically have to do user space because of how exciting Microsoft is about locking them out of the kernel is what I hear

malwaretech,

@HalvarFlake Basically everyone except Microsoft Defender does AFIK. With KPP preventing SSDT hooking, you're basically limited to kernel callbacks, filter drivers, and ETW. Only real viable way left to get good telemetry is user mode hooking

dymaxion,

@malwaretech
This just feels like an argument that we should demand that our OS vendors build proper EDR tooling, because it can't be done correctly by anyone else.
@HalvarFlake

malwaretech,

@dymaxion @HalvarFlake They tried that back when SSDT hooks were removed and Microsoft response was basically fart noises

dymaxion,

@malwaretech
Oh, I'm not saying they've done it — that's why it unfortunately is a demand. If we lived in a more perfect universe etc etc
@HalvarFlake

chort,

deleted_by_author

  • Loading...
  • ljrk,
    @ljrk@todon.eu avatar

    @chort @malwaretech @dymaxion @HalvarFlake Additionally, their EDR, I mean XDR, solution is incredibly slow to react to alerts or even display them.

    And while I agree with Halvar that in a perfect world we have introspection APIs... I'd also hope that in a perfect world, endpoint security would matter a lot less.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • InstantRegret
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • rosin
  • everett
  • Durango
  • Youngstown
  • slotface
  • cubers
  • kavyap
  • ngwrru68w68
  • ethstaker
  • JUstTest
  • mdbf
  • Leos
  • GTA5RPClips
  • osvaldo12
  • tester
  • modclub
  • khanakhh
  • cisconetworking
  • provamag3
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines