Always fun to see another EDR bypass. Remember the majority of EDR rules are signatures written by humans. Also remember that these vendors have a very broad customer base so they have to cover a broad range of generic signatures to catch them all. Which means it doesn’t take much to bypass.

Comments