#edr

6 posts· Last used 1d

Akamai security researchers have uncovered an interesting attack technique they call “Bring Your Own EDR.” The research demonstrates how a trusted, privileged EDR component can potentially become an attacker’s tool against the system it was designed to protect. In a SentinelOne case study, researchers found that exposed interfaces could be abused by an administrator to bypass Windows Protected Process Light protections and interact with highly protected processes. By chaining multiple techniques, they demonstrated how legitimate security software could potentially be turned into a powerful attack mechanism. The bigger lesson is important: security software itself is part of the attack surface. EDR solutions operate with extremely high privileges, which makes vulnerabilities, exposed interfaces, weak trust assumptions, and insecure management mechanisms particularly significant. Organizations should consider not only whether their security tools detect threats, but also how well those tools protect themselves from abuse. “Bring Your Own EDR” is an interesting evolution of the traditional BYOVD concept and another reminder that trusted software should never automatically be treated as inherently trustworthy. #Cybersecurity #EDR #EndpointSecurity #ThreatResearch #ZeroTrust #WindowsSecurity #SecurityResearch #InformationSecurity https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse
0
0
0
0
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. We expect those numbers to keep growing, as threat actors can weaponize any of thousands of available vulnerable drivers – some with public PoC exploits – while leveraging AI coding tools to adapt them, giving them a virtually endless supply. The report also details #ESETresearch findings from the Gentlemen leak. We found the gang uses a shared defense-evasion layer across its EDR killer suite – spanning in-house GentleKiller, third-party, and leaked tools – and can operationalize new BYOVD PoCs within days. While ransomware gangs are ramping up attacks (+50% YoY) only a minority of victims are willing to pay, with public reports putting that figure at just 14–28%. The total sum of ransom payments is also trending down, falling 8% from 2024 to 2025. For more on developments across the ransomware scene in H1 2026 – including gang infighting and successes in the fight against the gangs – read the full report: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
4
0
5
1
Using EDR is hard - especially if you’re not a cybersecurity expert. Radegast EDR is different. Our goal? Privacy-first and easy-to-use for anyone. To make it even simpler, we’ve just added an onboarding journey that guides you through the entire web Console, explains all the necessary terms, and gets you from first login to deployed detections in under a minute. Check out the project's website for more info: https://radegast.app/ GitHub: https://github.com/radegast-edr/ #RadegastEDR #OpenSource #CyberSecurity #EDR #InfoSec
0
1
0
0
Using EDR is hard - especially if you’re not a cybersecurity expert. Radegast EDR is different. Our goal? Privacy-first and easy-to-use for anyone. To make it even simpler, we’ve just added an onboarding journey that guides you through the entire web Console, explains all the necessary terms, and gets you from first login to deployed detections in under a minute. Check out the project's website for more info: https://radegast.app/ GitHub: https://github.com/radegast-edr/ #RadegastEDR #OpenSource #CyberSecurity #EDR #InfoSec
0
0
0
0
You've seen all posts