Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

How to Defeat EDRs in Usermode

Hack In The Box Security Conference via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore advanced techniques for bypassing Endpoint Detection and Response (EDR) systems in usermode during this 56-minute conference talk from the Hack In The Box Security Conference. Learn how defensive solutions have evolved over time and discover various EDR bypass methods, including PID spoofing, DLL blocking, userland unhooking, syscalls, and manual mapping. Watch as Jean-François demonstrates these bypasses using a custom-built EDR and C# with the D/Invoke framework, while emphasizing that the principles can be applied to other programming languages. In the second half, Alessandro presents his tool, Inceptor, which incorporates knowledge from previous presentations to bypass modern defenses in multiple languages with built-in obfuscation methods. Gain insights from two experienced security professionals, Alessandro Magnosi and Jean-François Maes, as they share their expertise and inspire attendees to learn from conferences and develop innovative cybersecurity solutions.

Syllabus

#HITBCW2021 D2 - How To Defeat EDRs In Usermode - Alessandro Magnosi & Jean Francois Maes

Taught by

Hack In The Box Security Conference

Reviews

Start your review of How to Defeat EDRs in Usermode

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.