>_0xFORUM
Sign in

EDR bypass writeups vs EDR as a telemetry source

in Defense10 replies1.4k views

I read bypass writeups as detection homework, not as a shopping list. Then I ask: would our telemetry have seen the setup, not the bypass?

If you only hunt the bypass, you missed the hour before the bypass.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 10 REPLIES

Please keep the hashes and drop the mystery zips. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection homework, not as a shopping list. Isolate the host too, or stop calling the guest isolated. I reproduced it on lab build 1081.

@labs

The screenshot is the useful part of the post. You wrote «I read bypass writeups as detection homework, not as a shopping list». That is the

Same wall I hit last quarter. Ā«EDR bypass writeups vs EDR as a telemetry sourceĀ» — specifically I read bypass writeups as detection homework, not as a shopping list. Firewall rules not in the repo are unreviewed code. I reproduced it on lab build 1268.

@iam_sammy

Please keep the hashes and drop the mystery zips. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection

The graph hid it. The listing did not. Trust the listing. The screenshot is the useful part of the post. Ā«EDR bypass writeups vs EDR as a telemetry sourceĀ» — specifically I read bypass writeups as detection homework, not as a shopping list. Firewall rules not in the repo are unreviewed code. I still have the snapshot named defe-188-pre.

@loader

Same wall I hit last quarter. Ā«EDR bypass writeups vs EDR as a telemetry sourceĀ» — specifically I read bypass writeups as detection homework

Calling the sticky 'priest talk' is how you earn a ban note. This matches a public n-day class from last patch Tuesday. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection homework, not as a shopping list. Allow-list entries expire. 90 days or they are a vulnerability. I still have the snapshot named defe-188-pre.

I will argue the opposite and then probably agree. You wrote «I read bypass writeups as detection homework, not as a shopping list». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Same class as the January thread, different binary.

@kelnnode

I will argue the opposite and then probably agree. You wrote «I read bypass writeups as detection homework, not as a shopping list». That is

Stop flexing an IDA license. The question was the unwind info. The screenshot is the useful part of the post. You wrote «I read bypass writeups as detection homework, not as a shopping list». That is the sentence I keep. Firewall rules not in the repo are unreviewed code. Did you force-create the function or did auto-analysis luck into it? Pinned a comment at 0x140004b71 in the listing.

If you only have the decompiler, you do not have the bug. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection homework, not as a shopping list. Allow-list entries expire. 90 days or they are a vulnerability. Version in my shot: current lab snapshot, not last year's blog.

@netsec

If you only have the decompiler, you do not have the bug. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as d

That is a vibe. I asked for a listing offset. This belongs in the first-hour ritual. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection homework, not as a shopping list. If debug requires turning the control off, the debug story is wrong. Same class as the March thread, different binary.

I disagree with the tone, not the bytes. On Ā«EDR bypass writeups vs EDR as a telemetry sourceĀ»: I read bypass writeups as detection homework, not as a shopping list. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. What did you key the join on — PID or process GUID? I will +rep a listing and āˆ’rep a vibe. That is the deal.

@patch

I disagree with the tone, not the bytes. On «EDR bypass writeups vs EDR as a telemetry source»: I read bypass writeups as detection homework

If you cannot paste bytes, you do not have a counterexample. I would have written the opposite conclusion a year ago. The load-bearing line: I read bypass writeups as detection homework, not as a shopping list. 3am isolation notes must fit on a page. Pinned a comment at 0x140000e94 in the listing.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.