Finding a dumb EDR tool which uses a kernel mode driver and user-land hooking with an analysis engine to determine if an executable is malicious or not.
Depending on the outcome of this analysis the driver will either allow a process to run or not, and the aim of the game is to bypass vulnerabilities to get our injector to run and spawn calc.exe
Note: It looks like this may have been based on original work by Ceri Coburn, so definitely check out his project also:
https://github.com/CCob/SylantStrike
https://ethicalchaos.dev/2020/05/27/l...
https://ethicalchaos.dev/2020/06/14/l...
** Find me at **
Twitter/X - / cyberraiju
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju
** Timestamps **
00:00 - EDR industry stats
00:26 - Orange Defense EDR post
00:52 - Getting setup
01:10 - Components of the EDR tool
01:30 - Building the project and comparing debug/release output
01:55 - SylantStrike DLL
02:36 - Looking at MyDumbEDRDLL
02:46 - Hooking
03:30 - Checking for RWX permissions
04:08 - Looking at MyDumbEDRDriver
04:25 - Device name and symbolic link
04:45 - DumbEDRAnalyzer named pipe
05:35 - Finding a vulnerability in MyDumbEDRDriver
06:03 - Examining the CreateProcessNotify callback
07:12 - CreationStatus message
07:35 - Finding a 2nd vulnerability in MyDumbEDRDriver
08:20 - Looking at MyDumbEDRRemoteInjector
08:34 - Jai does a derp
08:50 - RemoteInjector synopsis
09:49 - Looking at MyDumbEDRStaticAnalyzer
10:06 - Finding a vulnerability in MyDumbEDRStaticAnalyzer
10:29 - Finding a vulnerability in IAT checks
11:25 - Finding a vulnerability in string checks
11:57 - MyDumbEDRStaticAnalyzer synopsis
12:32 - Installing and running the EDR driver and executables
13:16 - Preparing notepad for injection
13:30 - EDR shutting down injection
13:55 - Reflecting on vulnerabilities
14:17 - L337 Hacking Skills
14:35 - Jai does a derp part 2
15:08 - Jai does a derp finale
15:53 - taskkill success
16:03 - Popping calc and getting the flag
16:20 - Examining ShellcodeInject
16:42 - Discussing other methods of bypassing EDR tooling
** Further Reading **
https://github.com/sensepost/mydumbedr
https://sensepost.com/blog/2024/sense...
Credits:
SFX by Pixabay
Music by Pixabay, Julius H., and Freccero (86349)
Icons by Icons8.