USENIX Security2025Top-tier venue
EvilEDR: Repurposing EDR as an Offensive Tool
Kotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten, Yury Zhauniarovich
Abstract
Endpoint Detection and Response (EDR) systems provide continuous monitoring, threat detection, and response capabilities. This has driven their widespread adoption in enterprises, making them a key part of an enterprise's security architecture. However, EDR systems are a double-edged sword, and in this study, we demonstrate how this class of systems can be employed for offensive use. Unlike prior studies that focused on evasion and tampering, we introduce the new concept of EDR repurposing, which we call EvilEDR. Our analysis shows that EvilEDR can be used to execute arbitrary commands via the response console, transfer tools, exfiltrate data, and passively collect system information to facilitate further exploitation and lateral movement. EvilEDR operates covertly, masquerading as a legitimate process and communicating seamlessly with trusted domains. Additionally, we show that EvilEDR can impair defenses by registering its own EPP as the default. It can also isolate the host from the network, severing telemetry and response channels essential for enterprise defense mechanisms. Fortunately, EvilEDR can be effectively detected and mitigated, and in this paper, we propose concrete and actionable defense strategies to achieve this.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on1
Related papers
- Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response ToolsFeng Dong, Shaofei Li, Peng Jiang, Ding Li et al.CCS 2023 · 24 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- On the Risk of Evidence Pollution for Malicious Social Text Detection in the Era of LLMsHerun Wan, Minnan Luo, Zhixiong Su, Guang Dai et al.ACL 2025 · 5 citations
- Loophole: Timing Attacks on Shared Event Loops in ChromePepe Vila, Boris KöpfUSENIX Security 2017 · 66 citations
- When AIOps Become "AI Oops": Subverting LLM-driven IT Operations via Telemetry ManipulationDario Pasquini, Evgenios M. Kornaropoulos, Giuseppe Ateniese, Omer Akgul et al.USENIX Security 2026 · 1 citation
