EDR bypassing via memory manipulation techniques

Authors

Connor Morley

Download report

Endpoint Detection & Response systems (EDR), delivered by in-house teams or as part of a managed service, are a feature of modern intrusion detection and remediation operations. This success is a problem for attackers, and malicious actors have worked to find new ways to evade EDR detection capabilities. As with all arms races, these approaches to evading detection are creative and effective. One of the primary methods utilized in modern attack frameworks, hands on keyboard operations and even malicious binaries revolves around memory manipulation.

Memory manipulation is nothing new; most readers will be familiar with process injection, thread hijacking, process hollowing and so on. That said, some recent tools/techniques are focused less on deployment and more on circumventing EDR telemetry acquisition techniques or alerting mechanisms. Elaborate hooking and exploitation of native functionality is now employed with impressive success rates.

This paper is broken down into three parts; the first will explain some of the memory techniques readily used by attackers to avoid detection in today’s landscape, and will explain how they work and why they may be chosen. The second and third parts will focus on methods to detect the utilization of such covert mechanisms, where telemetry for detection may be acquired, and some of the difficulties that may be encountered during the integration of these solutions.

What next?

Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.

Related Labs content

Find related content relating to this topic.

W/ラボ

Attack Detection Software Protection Threat intelligence

DarkGate Rises: New version of DarkGate malware hunts like a Duck but bites like a RAT

Source: https://labs.withsecure.com/publications/darkgate-rises

W/ラボ

Attack Detection Software Protection Threat intelligence

Reverse engineering a Lumma infection

Lumma is an information stealer that the WithSecure Detection and Response Team (DRT) have encountered several times. It has seen wider use over the past couple of years, and makes for an interesting threat to monitor.

W/ラボ

AI security Attack Detection Software Protection

Machine learning-driven malware analysis

With the rapid emergence of new malware variants, accurately classifying and attributing malware samples has become more challenging than ever