Fabian 12/1/2024

EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1

Read Original

This technical article, Part 1 of a series, examines methods to block Endpoint Detection and Response (EDR) agent communications, focusing on Microsoft Defender for Endpoint. It discusses existing techniques like Windows Firewall and Windows Filtering Platform, then introduces a 'novel' method using the Name Resolution Policy Table (NRPT) to tamper with DNS and prevent logging. The content is aimed at security professionals, red teams, and covers both offensive techniques and defensive detection considerations.

EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

2
Designing Design Systems
TkDodo Dominik Dorfmeister 2 votes
3
Introducing RSC Explorer
Dan Abramov 1 votes
5
Fragments Dec 11
Martin Fowler 1 votes
6
Adding Type Hints to my Blog
Daniel Feldroy 1 votes
7
Refactoring English: Month 12
Michael Lynch 1 votes
9