How to Defeat EDRs in Usermode
Offered By: Hack In The Box Security Conference via YouTube
Course Description
Overview
Explore advanced techniques for bypassing Endpoint Detection and Response (EDR) systems in usermode during this 56-minute conference talk from the Hack In The Box Security Conference. Learn how defensive solutions have evolved over time and discover various EDR bypass methods, including PID spoofing, DLL blocking, userland unhooking, syscalls, and manual mapping. Watch as Jean-François demonstrates these bypasses using a custom-built EDR and C# with the D/Invoke framework, while emphasizing that the principles can be applied to other programming languages. In the second half, Alessandro presents his tool, Inceptor, which incorporates knowledge from previous presentations to bypass modern defenses in multiple languages with built-in obfuscation methods. Gain insights from two experienced security professionals, Alessandro Magnosi and Jean-François Maes, as they share their expertise and inspire attendees to learn from conferences and develop innovative cybersecurity solutions.
Syllabus
#HITBCW2021 D2 - How To Defeat EDRs In Usermode - Alessandro Magnosi & Jean Francois Maes
Taught by
Hack In The Box Security Conference
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network