4 ms·
The significant thing here is that the technique should interfere with data collected by all common EDR software, rather than requiring specific tailoring for e
by _23sd 3y ago
The significant thing here is that the technique should interfere with data collected by all common EDR software, rather than requiring specific tailoring for each one like most EDR bypass tricks. I’m curious about why the API protections present in Windows 11 couldn’t be brought to Windows 10.
>Multiple pieces of evidence show that Microsoft is aware of the weakness, but is not changing the API behavior retroactively on Windows 10, likely due to retro-compatibility issues.
If MS actually says that, it seems like a lame excuse.
- _8j50 3y agoNot just a lame excuse but downright irresponsible and reckless. They should make the fix an opt-in registry flag controlled mitigation, similar to the PE signature bypass mitigation. They want to profit off of vulnerabilities by forcing upgrades. They make great products but man do they play dirty. After azure ad was hackes they rebranded and still charge an arm and leg to access your own tenant's security logs (even if you pay for storage and traffic!).