❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayPentest/Red Team

Finding and exploiting process killer drivers with LOL for 3000$

By: Author
9 June 2023 at 13:42
This article describes a quick way to find easy exploitable process killer drivers. There are many ways to identify and exploit process killer drivers. This article is not exhaustive and presents only one (easy) method. Lately, the use of the BYOVD technique to kill AV and EDR agents seems trending. The ZeroMemoryEx Blackout project, the Terminator tool sold (for 3000$) by spyboy are some recent examples. Using vulnerable drivers to kill AV and EDR is not brand new, it’s been used by APTs, Red Teamers, and ransomware gangs for quite some time.
❌
❌