‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware
DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows’ most protected processes, ultimately shielding malicious payloads behind the endpoint agent’s own tamper protection. SentinelOne has patched the underlying issue in Agent 26.1.1.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.