EDR bypassing via memory manipulation techniques

Authors

Connor Morley

Download report

Endpoint Detection & Response systems (EDR), delivered by in-house teams or as part of a managed service, are a feature of modern intrusion detection and remediation operations. This success is a problem for attackers, and malicious actors have worked to find new ways to evade EDR detection capabilities. As with all arms races, these approaches to evading detection are creative and effective. One of the primary methods utilized in modern attack frameworks, hands on keyboard operations and even malicious binaries revolves around memory manipulation.

Memory manipulation is nothing new; most readers will be familiar with process injection, thread hijacking, process hollowing and so on. That said, some recent tools/techniques are focused less on deployment and more on circumventing EDR telemetry acquisition techniques or alerting mechanisms. Elaborate hooking and exploitation of native functionality is now employed with impressive success rates.

This paper is broken down into three parts; the first will explain some of the memory techniques readily used by attackers to avoid detection in today’s landscape, and will explain how they work and why they may be chosen. The second and third parts will focus on methods to detect the utilization of such covert mechanisms, where telemetry for detection may be acquired, and some of the difficulties that may be encountered during the integration of these solutions.

What next?

Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.

Contenus associés

Découvrez d’autres contenus en rapport avec ce sujet.

Article

Endpoint Security Malware Ransomware Threat intelligence

Stolen creds and stinging loaders: An initial access campaign via SEO poisoning

Blog post

AI security Software Protection Threat intelligence

GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations

Article

Endpoint Security Threat intelligence

The ‘vice’ in tech advice: ClickFix-style commands disguised as tech tips across social media platforms and beyond