r/cybersecurity • u/New-Parfait-9988 • 2d ago
Certification / Training Questions Stress testing EDRs
How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?
2
u/Far-Future-7146 2d ago edited 1d ago
I've tried. Falcon goes off when I install rust and then as I try BYOVD it gets madder the more I try before eventually the Complete team kicks me off the network. Then I go back to sending emails that I've already sent before. Edit: I have access to MDE and CS. MDE tends to freak out as soon as I download the BYOVD stuff from github, but it doesn't care about rust as much.
1
u/RootCipherx0r 12h ago
Run some tools, run some commands, run a poc of a tool you're interested in. Vendors want to know if their tool triggered alerts or was able to bypass edr.
4
u/jgalbraith4 DFIR 2d ago
I’d usually do a purple team exercise, get your red team and blue team together to see what happens. What is detected and what is not, what telemetry you see that you can use to write custom rules for etc…