Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

The Dark Side of EDR - Repurposing EDR as an Offensive Tool

Black Hat via YouTube

Overview

Explore a groundbreaking approach to cybersecurity in this 43-minute Black Hat conference talk that delves into the potential vulnerabilities of Endpoint Detection and Response (EDR) solutions. Learn how incorrect deployment of EDR systems can be exploited by malicious actors, focusing on a unique methodology that involves controlling the EDR to execute code within its context. Discover how this technique allows for covert and persistent operations, significantly impacting organizational security. Examine a case study on Palo Alto Networks Cortex XDR, demonstrating how to manipulate the system to bypass security measures and transform it into a stealthy, persistent form of malware. Gain insights into overcoming machine learning detection modules, behavioral modules, real-time prevention rules, and filter-driver protection. Understand advanced techniques for exfiltrating sensitive user credentials, establishing robust persistence, encrypting entire machines, dumping LSASS memory, concealing malicious activity, and exploiting XDR comprehensively. Explore the implications of this novel attack vector and its impact on the relationship between attackers and XDR, addressing a critical aspect of EDR security previously unexplored.

Syllabus

The Dark Side of EDR: Repurpose EDR as an Offensive Tool

Taught by

Black Hat

Reviews

Start your review of The Dark Side of EDR - Repurposing EDR as an Offensive Tool

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.