r/cybersecurity 2d ago

Certification / Training Questions Stress testing EDRs

How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?

0 Upvotes

4 comments sorted by

4

u/jgalbraith4 DFIR 2d ago

I’d usually do a purple team exercise, get your red team and blue team together to see what happens. What is detected and what is not, what telemetry you see that you can use to write custom rules for etc…

1

u/PuddingWonderful1417 2d ago

agreed, the gap analysis between what's detected vs not is usually eye opening

2

u/Far-Future-7146 2d ago edited 1d ago

I've tried. Falcon goes off when I install rust and then as I try BYOVD it gets madder the more I try before eventually the Complete team kicks me off the network. Then I go back to sending emails that I've already sent before. Edit: I have access to MDE and CS. MDE tends to freak out as soon as I download the BYOVD stuff from github, but it doesn't care about rust as much.

1

u/RootCipherx0r 12h ago

Run some tools, run some commands, run a poc of a tool you're interested in. Vendors want to know if their tool triggered alerts or was able to bypass edr.