Skip to content

Topic

EDR Evasion and Defense Bypass

Techniques that disable, blind, or boot around endpoint detection and response controls, including Safe Mode abuse.

Current stories

security1 publisher

A signed UEFI shell can disable the Secure Boot that trusted it

On a September 10 podcast, Eclypsium researchers walked from vulnerable signed UEFI shells to Fire Ant binaries wearing EDR agent names. The common thread is verification: a defender can check very little of that stack alone.

Publishers:eclypsium.com

Reality

Evidence30
Adoption30
Hype gap+15
Incentives78
Confidence45
security1 publisher

Qilin hands affiliates the ransom wallet before the core team takes its cut

Group-IB puts the Qilin affiliate cut at up to 80 percent, and KELA logged a change that routes victim payments through affiliate wallets first, which says more about the operation's incentives than its thin public tradecraft record does.

Publishers:blog.bushidotoken.net

Reality

Evidence54
Adoption63
Hype gap+14
Incentives71
Confidence57