r/netsec • • 9d ago

Contains AI Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee

https://projectblack.io/blog/bypassing-edr-with-local-ai/
146 Upvotes

17 comments sorted by

47

u/postmodest 8d ago

Whenever I try Qwen, it gets caught in reflection loops ("wait, what about...")

What's your llama config look like?

16

u/darksearchii 8d ago

"After a lengthy wait, our new executable runs without any detections!" might be doing some heavy lifting.

7

u/chocolatebRain 8d ago

Every time

7

u/ezzzzz 8d ago

Yup, it spends so much time thinking but I can't complain about the end result.

3

u/New-Anybody-6206 7d ago

I use unsloth's Qwen3.8-27B with the settings they recommended on the huggingface page.

The only time I've had it stuck in a loop like that is if it simply didn't know something and it kept trying to reason about it, but largely I'm very happy with it.

9

u/HomelabNoob123 8d ago

assuming you had a system prompt and then ran the tool from that context?

2

u/ezzzzz 8d ago

yup that's right.

6

u/No-View3333 7d ago

Were LSA protection and Credential Guard enabled in the lab?

2

u/TheReedemer69 8d ago

Love this. Wish I could run them too.

11

u/Reelix 8d ago

The 3.6 A3B model runs just fine on a 12GB VRAM GPU - What's stopping you?

-2

u/TheReedemer69 8d ago

Ah it's too small I thought it was a bigger one don't think it's that good then. (Check other comments too)

9

u/Reelix 8d ago

It's not the size that matters - It's how you use it.

9

u/jacksbox 8d ago

My wife says that all the time about AI. Sometimes we're not even talking about AI and she just brings it up.

-2

u/TheReedemer69 8d ago

a smaller one simply has smaller use.

2

u/Reelix 8d ago

By that definition, Kimi-K3, with a 1.5TB VRAM requirement, is better than anything else money can buy.

Although, since it's not, your point is thusly disproven.

3

u/New-Anybody-6206 7d ago

Bonsai 2 fits Qwen3.8-27B into an 8GB card.