🎙️La légende libérienne George Weah :
« Si vous voulez la vérité… celui qui quitte le terrain et se retire du match, puis revient et est considéré comme vainqueur… la loi est claire, il est perdant. Le football ne se joue pas comme ça… Le Maroc a défendu son droit et l’a obtenu, alors félicitations à lui pour le titre »
Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳
The first samples of #EDRFreeze that landed on VirusTotal were already detected by our existing rules – even though we hadn’t written anything specific for it. The reason is that the authors reused previously documented techniques we had already covered in our generic YARA rules
Some additional remarks:
- EDR-Freeze is another userland EDR killer abusing WerFaultSecure to suspend EDR/AV processes without BYOVD
- Early VirusTotal submissions had very low AV detection (5/73)
- The precompiled release binary was uploaded multiple times and eventually reached 22/73 detections
- Other builds of the tool still get just 8–10 detections
- Nothing new here: AV products still take their time reacting to publicly dropped tools
- We’ve now added blocking rules for this tool to our Sysmon config, using the imphash
- This means that if you use Sysmon with our config and a recent enough version, this tool gets blocked on write (via FileBlockExecutable)
EDR-Freeze
https://t.co/pyz9FFJsFu
VT samples (with our detections):
2c8fbd0f7fd0ed8ebcacb087c8faa6f3
768348397c70e19075cbb10a24cf9d83
c57067816def020b6984e7c2bee9be31
Sysmon Config (now with rules for EDR-Freeze):
https://t.co/f7kxUDwFbi
Sysmon FileBlockExecutable docs:
https://t.co/kZsbEd36fB