Blasting Event-Driven Cornucopia: WMI-based User-Space Attacks Blind SIEMs and EDRs
Security solutions engineers always find new ways to monitor OS events to mitigate threats on endpoints. These approaches typically reuse different built-in Windows mechanisms that were never designed with security first in mind. At Black Hat Europe 2021, we publicly showed how to blind an entire class of endpoint security products by disabling ETW. Our current research focus is Windows Management Instrumentation (WMI), a mechanism that allows filtering without registering kernel callbacks...
By: Andrey Golchikov , Igor Korkin , Claudiu Teodorescu
Full Abstract & Presentation Materials: #blasting-event-driven-cornucopia-wmi-based-user-space-attacks-blind-siems-and-edrs-27211
1 view
0
0
5 months ago 00:05:06 1
Max Cooper feat. Kwake Bass - Fibonacci Sequence (Official video by Yoshi Sodeoka)
5 months ago 00:10:46 1
BBC’s worst Israel coverage yet!
7 months ago 00:18:44 1
Tower of Power: NPR Music Tiny Desk Concert
9 months ago 00:03:22 1
90-year-old Bugatti Type 35B Grand Prix car driven on the limit!
10 months ago 00:01:15 1
Russian-controlled tank laden with bombs explodes near Ukrainian frontline
10 months ago 00:12:23 4
BASE Jumping from a Human Catapault - Heliboogie 2023 Day 3
10 months ago 00:00:43 20
Doomed Neutron Stars Create Blast of Light and Gravitational Waves
2 years ago 00:39:17 1
Blasting Event-Driven Cornucopia: WMI-based User-Space Attacks Blind SIEMs and EDRs
3 years ago 00:03:10 34
B-Girl Nicka vs B-Girl Emilka | Outbreak Europe | The Legits Blast 2021
3 years ago 00:04:49 1
B-Boy Lagaet vs. B-Boy Nord Diamond | Outbreak Europe | The Legits Blast 2021
3 years ago 00:02:57 35
B-Boy JohnnyFox vs. B-Boy Tirock | Outbreak Europe | The Legits Blast 2021
3 years ago 00:03:40 114
B-Boy Nord Diamond vs. B-Boy Tirock | Outbreak Europe | The Legits Blast 2021