EvilEDR: Repurposing EDR as an Offensive Tool
Kotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten, Yury Zhauniarovich
摘要
Endpoint Detection and Response (EDR) systems provide continuous monitoring, threat detection, and response capabilities. This has driven their widespread adoption in enterprises, making them a key part of an enterprise's security architecture. However, EDR systems are a double-edged sword, and in this study, we demonstrate how this class of systems can be employed for offensive use. Unlike prior studies that focused on evasion and tampering, we introduce the new concept of EDR repurposing, which we call EvilEDR. Our analysis shows that EvilEDR can be used to execute arbitrary commands via the response console, transfer tools, exfiltrate data, and passively collect system information to facilitate further exploitation and lateral movement. EvilEDR operates covertly, masquerading as a legitimate process and communicating seamlessly with trusted domains. Additionally, we show that EvilEDR can impair defenses by registering its own EPP as the default. It can also isolate the host from the network, severing telemetry and response channels essential for enterprise defense mechanisms. Fortunately, EvilEDR can be effectively detected and mitigated, and in this paper, we propose concrete and actionable defense strategies to achieve this.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper1
相关 Paper
- Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response ToolsFeng Dong, Shaofei Li, Peng Jiang, Ding Li 等CCS 2023 · 被引用 24 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- On the Risk of Evidence Pollution for Malicious Social Text Detection in the Era of LLMsHerun Wan, Minnan Luo, Zhixiong Su, Guang Dai 等ACL 2025 · 被引用 5 次
- Loophole: Timing Attacks on Shared Event Loops in ChromePepe Vila, Boris KöpfUSENIX Security 2017 · 被引用 66 次
- When AIOps Become "AI Oops": Subverting LLM-driven IT Operations via Telemetry ManipulationDario Pasquini, Evgenios M. Kornaropoulos, Giuseppe Ateniese, Omer Akgul 等USENIX Security 2026 · 被引用 1 次
