Threat actors know that most organizations are going to have some type of endpoint defenses, whether it’s next-generation antivirus (NGAV), endpoint detection and response (EDR), or an endpoint protection platform solution (EPP). Getting around these defenses is part of their playbook and tradecraft, covered in frameworks like MITRE ATT&CK under the Defense Evasion tactic and techniques like Impair Defense (T.1652). These actors are moving beyond merely evading detection and even basic impairment to disabling threat-detection tools. This allows adversaries to create a "dark zone" where they can establish footholds, move laterally, exfiltrate data, and deploy ransomware with zero visibility to IT and security teams. This isn't just evasion; it’s an active destruction of the security stack. Attacker tradecraft and tools: How they’re wrecking antivirus and EDR There are multiple methods used by threat attackers as part of their tradecraft to impair, block, and disable endpoint security controls. Here’s a list of the most common approaches: - Blocking AV and EDR communications Attackers can blind EDR communications using malicious Windows Firewall rules via two approaches: directly creating the firewall rules, which is a bit noisy but effective, or using the Windows Filtering Platform (WFP) to create hidden firewall rules. These rules specifically block the EDR agent from communicating with its platform. The agent continues to run locally, giving the user a false sense of security, but it's effectively "silenced" and can't send any telemetry or alerts. Tools like EDRSandblast and EDRSilencer allow attackers to easily abuse Windows Firewall as part of their defense-evasion tradecraft. - Escalate privileges, uninstall agents Once an attacker lands on an endpoint, getting administrative privileges gives them much more latitude to install their tools, apply their tradecraft, and get to work. Sometimes, they might not even have to go through the effort if permissions aren’t properly secured,
Threat Actor Defense Evasion: How Attackers Disable AV & EDR | Huntress
Read the original article
huntress.com →