EDR Silencers and Beyond: Exploring Methods to Block EDR Communication - Part 1
Read OriginalThis technical article, Part 1 of a series, examines methods to block Endpoint Detection and Response (EDR) agent communications, focusing on Microsoft Defender for Endpoint. It discusses existing techniques like Windows Firewall and Windows Filtering Platform, then introduces a 'novel' method using the Name Resolution Policy Table (NRPT) to tamper with DNS and prevent logging. The content is aimed at security professionals, red teams, and covers both offensive techniques and defensive detection considerations.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser