home.social

#byovd — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #byovd, aggregated by home.social.

  1. Cruciferra: il crypter da 2.000 dollari al mese che uccide gli EDR e fa sparire il malware dal disco

    Proofpoint svela Cruciferra, servizio di crypter venduto su forum underground che combina BYOVD, syscall indiretti e una variante di Process Ghosting per proteggere AsyncRAT, Agent Tesla, Remcos e altri RAT usati da gruppi come TA4922.

    insicurezzadigitale.com/crucif

  2. Ransomware Gang Disables Security Software with GentleKiller Framework

    Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for…

    osintsights.com/ransomware-gan

    #Ransomware #Gentlekiller #Byovd #EndpointDetectionAndResponse #EdrKiller

  3. BYOVD-атаки на ядро Windows через драйверы: разбираю механику, воспроизвожу, строю защиту

    Вы настроили Sysmon, у вас работает EDR, события летят в SIEM. Создаётся процесс, вы видите Event ID 1. Загружается DLL, Event ID 7. Всё под контролем. А теперь кто-то загружает в систему один .sys-файл. Обычный, подписанный, из прошлого века. И события пропадают. Не потому что Sysmon упал или EDR отключили. Они работают. Просто ядро Windows больше не считает нужным им что-то рассказывать. Я залез внутрь, чтобы понять, как это устроено. Поднял WinDbg, подключился к ядру, нашёл структуры, где хранятся callback'и мониторинга. Обнулил их, повторив технику руткита Lazarus. Sysmon на месте, PID живой, но лог пустой. Меня зовут Роман Мгоев, я специалист по анализу киберугроз в Альфа-Банке, в статье пройду этот путь целиком: начиная с архитектуры колец защиты Windows, byte-патчей в памяти ядра и разбора FudModule от Lazarus обеих версий, до свежих техник zerosalarium и разбора публичных тулкитов, а в конце поделюсь семью направлениями детектирования с готовыми правилами для SIEM. Отдельный блок — про аудит драйверов, которых ещё нет ни в одной базе.

    habr.com/ru/companies/alfa/art

    #BYOVD #EDR #Windows_kernel #Sysmon #SIEM #Lazarus #ransomware #reverse_engineering #SOC #detection_engineering

  4. 10 популярных техник обхода EDR

    Алексей Баландин, Security Vision На сегодняшний день невозможно представить защиту конечных точек без системы EDR, которая, в отличие от устаревшего антивируса, основана в первую очередь на поведенческом анализе происходящих в системе событий. Потребность в этой системе резко возросла за последние 10 лет в связи с тем, что угрозы совершенствуются из года в год. Давно стало очевидно, что эффективно противостоять атакующим можно не столько за счет статического анализа кода, сигнатурного метода, сколько за счет изучения, анализа и блокировки их поведенческих паттернов, используемых тактик, техник и процедур. Этим и занимается класс продуктов EDR и активно развивается за счет постоянного пополнения базы знаний о новых методах атак. Обратной стороной медали является то, что атакующие не стоят на месте и разрабатывают все новые способы обхода и противодействия EDR. Далее рассмотрим техники обхода EDR, которые были наиболее популярны у атакующих за последние 5 лет.

    habr.com/ru/companies/security

    #edr #byovd #lolbas #обход_защиты #обход_антивируса

  5. [Перевод] Техники обхода систем обнаружения: маскировка путей и BYOVD

    Вакансии по пентесту всё чаще требуют не только понимания принципов работы ключевых СЗИ (WAF, EDR, NAC), но и практических навыков их обхода. То же самое касается EDR/AV. В реальных отчётах о кибератаках также регулярно упоминается, как злоумышленники обходят средства защиты и остаются незамеченными. Предлагаем рассмотреть пару приемов таких обходов и проверить, готовы ли ваши системы защиты к подобным вызовам.

    habr.com/ru/companies/cloud4y/

    #информационная_безопасность #edr #системы_защиты #мониторинг #маскировка_путей #byovd #символические_ссылки

  6. #BYOVD Attack: Researchers found a flaw in Checkpoint’s ZoneAlarm antivirus driver that could let attackers bypass Windows security and steal data.

    Read: hackread.com/checkpoint-zoneal

    #CyberSecurity #ZoneAlarm #Checkpoint #AntiVirus

  7. #BYOVD attacks are slowly becoming more common for threat actors to escalate privilege and kill security tools.
    Make sure you're #ThreatHunting for new Vulnerable Drivers!
    Win 11 now has a Vulnerable Driver Blocklist feature, however, it's only updated in major updates so you still need to monitor for recently discovered Vulnerable Drivers.

    Recent Vuln Driver: bleepingcomputer.com/news/secu

    Known Vuln Drivers: loldrivers.io/

    Vuln Driver Blocklist: learn.microsoft.com/en-us/wind

    #IncidentResponse #ransomware #ThreatDetection

  8. Another week, another newsletter - catch up on the week's infosec news here:

    opalsec.substack.com/p/soc-gou

    Researchers have found that nearly two years on, 2 in 3 installs of #Apache #Superset are still using default Flask Secret Keys - a configuration flaw which would allow an attacker to forge session cookies and access said servers with full administrative privileges.

    #Kritec is a commodity #skimmer found installed on compromised #Magecart sites, with its code heavily obfuscated and customised to match the site's aesthetic in order to con users out of credit card details.

    #FIN7 look to be popping instances of the #Veeam backup software that are unpatched for a recent vulnerability; a revised #ViperSoftX #infostealer now targets #1password and #keepass password vaults, and #TA505 deliver a new infostealer through a #GoogleAds campaign

    #LockBit & #CL0P ransomware affiliates have been abusing a month-old vulnerability in the #PaperCut print management software to drop ransomware. With the cat out of the bag, security researchers have decided now is a great time to drop a PoC exploit on Github - I mean, why not let the skiddies get in on the action too, right?

    The #blueteam have some great research worth reading on #Smishing via #AWS; detections for #SliverC2 and different implementations of #PsExec, as well as #Sigma integration for #SentinelOne and a #KQL hack for monitoring LOLDrivers.

    Have a great week ahead folks, I hope this newsletter proves helpful!

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #newsletter #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #flask #python #fraud #malvertising #clop #PoC #exploit #securityresearch #LOLBAS #LOLBIN #BYOVD