mirror of
https://github.com/senzee1984/EDRPrison
synced 2026-08-09 13:09:24 +00:00
Update README.md
This commit is contained in:
@@ -39,34 +39,43 @@ EDRPrison offers several enhancements and improvements over its predecessors, ma
|
||||
The following approaches can be used to detect or mitigate the use of EDRPrison. However, depending on the environment, some of these detections could result in false positives (FP).
|
||||
|
||||
### Driver Load Event
|
||||
- If the WinDivert driver is not already installed on the system, EDRPrison will install the callout driver upon first execution. Both the OS and telemetry systems will log this event.
|
||||
|
||||
If the WinDivert driver is not already installed on the system, EDRPrison will install the callout driver upon first execution. Both the OS and telemetry systems will log this event.
|
||||
|
||||
### Existence of WinDivert Files
|
||||
- EDRPrison and other programs dependent on WinDivert require the presence of WinDivert64.sys and WinDivert.dll on the disk. Monitoring for these files can help in detecting such programs.
|
||||
|
||||
EDRPrison and other programs dependent on WinDivert require the presence of WinDivert64.sys and WinDivert.dll on the disk. Monitoring for these files can help in detecting such programs.
|
||||
|
||||
### WinDivert Usage Detection Tools
|
||||
- Tools like [WinDivertTool](https://github.com/basil00/WinDivertTool) can detect processes that are currently utilizing the Windows Filtering Platform (WFP).
|
||||
|
||||
Tools like [WinDivertTool](https://github.com/basil00/WinDivertTool) can detect processes that are currently utilizing the Windows Filtering Platform (WFP).
|
||||
|
||||
### Packet Drop/Block Actions Against EDR Processes
|
||||
- Elastic has a detection [rule](https://www.elastic.co/guide/en/security/current/potential-evasion-via-windows-filtering-platform.html) that can identify packet drop or block actions against security software processes, which can indicate the presence of EDRPrison.
|
||||
|
||||
Elastic has a detection [rule](https://www.elastic.co/guide/en/security/current/potential-evasion-via-windows-filtering-platform.html) that can identify packet drop or block actions against security software processes, which can indicate the presence of EDRPrison.
|
||||
|
||||
### Review Registered WFP Providers, Filters, and Callouts
|
||||
- Tool [WFPExplorer](https://github.com/jdu2600/WFPExplorer) assists administrators in reviewing active WFP sessions, registered callouts, and filters.
|
||||
|
||||
Tool [WFPExplorer](https://github.com/jdu2600/WFPExplorer) assists administrators in reviewing active WFP sessions, registered callouts, and filters.
|
||||
|
||||
### Adminless
|
||||
- A potential future feature could add additional protections for driver installation, further enhancing the security against unauthorized use of drivers like WinDivert.
|
||||
|
||||
A potential future feature could add additional protections for driver installation, further enhancing the security against unauthorized use of drivers like WinDivert.
|
||||
|
||||
# Red Team Strategies to Subvert Detections
|
||||
From a red team perspective, several strategies can be employed to subvert the aforementioned detections, depending on the environment's security configurations.
|
||||
|
||||
### Seek An Alternative To WinDivert
|
||||
- If WinDivert is considered malicious in the environment, alternative signed, open-source drivers can be used. These alternatives should have fewer records of malicious use and still support packet interception, reinjection, and other manipulation techniques.
|
||||
|
||||
If WinDivert is considered malicious in the environment, alternative signed, open-source drivers can be used. These alternatives should have fewer records of malicious use and still support packet interception, reinjection, and other manipulation techniques.
|
||||
|
||||
### Reuse An Installed Or Built-in WFP Callout Driver
|
||||
- In environments where external drivers are unauthorized unless approved, it is challenging but feasible to reverse-engineer an installed or built-in WFP callout driver. By reusing its callout functions, red teamers can leverage existing drivers. Many security software solutions include their own WFP callout drivers that can be repurposed.
|
||||
|
||||
In environments where external drivers are unauthorized unless approved, it is challenging but feasible to reverse-engineer an installed or built-in WFP callout driver. By reusing its callout functions, red teamers can leverage existing drivers. Many security software solutions include their own WFP callout drivers that can be repurposed.
|
||||
|
||||
### Change Action To Intercepted Packets
|
||||
- Instead of blocking or dropping intercepted packets, red teamers can redirect or proxy them. This method can avoid detection rules focused on packet drop or block actions, while still achieving the desired interference with EDR processes.
|
||||
|
||||
Instead of blocking or dropping intercepted packets, red teamers can redirect or proxy them. This method can avoid detection rules focused on packet drop or block actions, while still achieving the desired interference with EDR processes.
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user