No EDRs were harmed while making this talk

No ratings

Presented at BSides Tallinn 2024 by

In this talk we'll explore how Red Teams can and do evade Endpoint Detection and Response (EDR) systems. First, we'll look at how EDRs are set up and used in various environments. We'll break down their components and how they work & communicate. Next, we'll dive into common malware functionalities and the different ways EDRs internally try to detect them. The main focus will be on the actual techniques used for avoiding detection and how they can be implemented. We'll cover how different detection scenarios are handled and also some more generic bypasses that still work against advanced EDR systems. We'll also have live demos to show these techniques in action if demo gods allow.