daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

edr-bypass.md (3904B)


      1 ---
      2 title: "Endpoint Detection and Response"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/evasion/edr-bypass.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/edr-bypass.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Endpoint Detection and Response
     12 
     13 Endpoint Detection and Response (EDR) is a security solution that combines real-time monitoring, data collection, and advanced analytics to detect, investigate, and respond to cyber threats at the endpoint level. Leveraging machine learning algorithms and behavioral analysis, EDR tools can identify malicious activities, automate containment and remediation actions, and provide forensic insights to enhance an organization's overall security posture.
     14 
     15 ## Static Detection
     16 
     17 **Mechanism**: Static detection is a security technique used in EDR and antivirus software that analyzes files and applications without executing them, typically based on predefined signatures or known malicious patterns.
     18 
     19 **Bypass**:
     20 
     21 - Obfuscate strings
     22 - Dynamically resolving strings
     23 - Dynamically resolving imports, reducing the `Import Address Table` (IAT)
     24 - Custom `GetProcAddress` and `GetModuleHandle`
     25 - API Hashing
     26 
     27 ## User Behavioural Analysis
     28 
     29 **Mechanism**: User Behavioral Analysis (UBA) monitors and analyzes user activities and patterns to detect anomalies and potential threats.
     30 
     31 **Bypass**:
     32 
     33 - Learning about OPSEC methods
     34 
     35 ## Usermode Windows Function Monitoring
     36 
     37 **Mechanism**: Usermode Windows Function Monitoring is a technique that tracks and analyzes the execution of Windows API (Application Programming Interface) calls and functions within user space processes.
     38 
     39 **Bypass**:
     40 
     41 - Unhooking
     42 - Indirect syscalls
     43 
     44 ## Call Stack Analysis
     45 
     46 **Mechanism**: Checking the origin of function calls via the Call Stack chain
     47 
     48 **Bypass**:
     49 
     50 - TODO
     51 - TODO
     52 
     53 ## Process Analysis
     54 
     55 **Mechanism**: Process analysis includes inspecting memory regions, identifying remote process access, and assessing child processes to gain insights into process relationships, uncover hidden or suspicious activities.
     56 
     57 **Bypass**:
     58 
     59 - Avoid RWX memory region (RW->RX)
     60 - Break parent-child link (e.g: word.exe spawning cmd.exe)
     61 - TODO
     62 
     63 ## Kernel Callbacks
     64 
     65 **Mechanism**: Kernel callbacks in the context of Endpoint Detection and Response (EDR) are functions registered by kernel drivers that get triggered in response to specific events or actions within the operating system's kernel.
     66 
     67 **Bypass**:
     68 
     69 - TODO
     70 
     71 ## WDAC to Disable EDR Components
     72 
     73 Place the WDAC policy `SiPolicy.p7b` inside `C:\Windows\System32\CodeIntegrity\` and reboot the machine.
     74 
     75 ```ps1
     76 smbmap -u Administrator -p P@ssw0rd -H 192.168.4.4 --upload "/home/kali/SiPolicy.p7b" "ADMIN\$/System32/CodeIntegrity/SiPolicy.p7b"
     77 smbmap -u Administrator -p P@ssw0rd -H 192.168.4.4 -x "shutdown /r /t 0"
     78 ```
     79 
     80 Using Krueger a .NET post-exploitation tool.
     81 
     82 - [logangoins/Krueger](https://github.com/logangoins/Krueger) - Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC
     83 
     84     ```ps1
     85     inlineExecute-Assembly --dotnetassembly C:\Tools\Krueger.exe --assemblyargs --host ms01
     86     ```
     87 
     88 ## References
     89 
     90 - [Flying Under the Radar: Part 1: Resolving Sensitive Windows Functions with x64 Assembly - theepicpowner - Apr 24, 2024](https://theepicpowner.gitlab.io/posts/Flying-Under-the-Radar-Part-1/)
     91 - [Malware AV/VM evasion - part 16: WinAPI GetProcAddress implementation. Simple C++ example - cocomelonc](https://cocomelonc.github.io/malware/2023/04/16/malware-av-evasion-16.html)
     92 - [Custom GetProcAddress And GetModuleHandle Implementation (X64) - daax - December 15, 2016](https://revers.engineering/custom-getprocaddress-and-getmodulehandle-implementation-x64/)
     93 - [Weaponizing WDAC: Killing the Dreams of EDR - Jonathan Beierle and Logan Goins - December 20, 2024](https://beierle.win/2024-12-20-Weaponizing-WDAC-Killing-the-Dreams-of-EDR/)