Перейти к содержимому

Silent Intruders: Dissecting EDR Bypass Strategies in APT Attacks - by Chao Wei-Chieh

Infosec In the City

0:00 / 0:00

Silent Intruders: Dissecting EDR Bypass Strategies in APT Attacks - by Chao Wei-Chieh

1 883 просмотра · 1 год назад
Infosec In the City
1,78 тыс. подписчиков
1 883 просмотра · 1 год назад
Speaker: Chao Wei-Chieh, Senior Cyber Security Researcher, CyCraft This talk explores how Advanced Persistent Threat (APT) groups employ sophisticated methods to bypass Endpoint Detection and Response (EDR) systems, a critical line of defense in modern cybersecurity. We will delve into three real-world incidents, each showcasing a distinct evasion tactic: hooking EDR processes, disrupting EDR communication, and deploying EDR-mimicking malwares. By dissecting these techniques, we provide valuable insights for blue teams to enhance their defenses against evolving APT threats. We conclude by discussing the broader cybersecurity implications and the need for continuous adaptation to counter these evolving threats. For more information about Infosec In the City, SINCON https://www.infosec-city.com/