<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Edr-Bypass on CuraSec</title><link>https://curasec.metacog.co.kr/tags/edr-bypass/</link><description>Recent content in Edr-Bypass on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 11:41:22 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/edr-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>UAT-10147 Deploys SPECTRE Malware with EDR Bypass and Linux Rootkit</title><link>https://curasec.metacog.co.kr/insights/2026-08-24-uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-wi/</link><pubDate>Mon, 24 Aug 2026 11:41:22 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-24-uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-wi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel Linux rootkit and EDR bypass technique targeting web servers is worth understanding for hardening posture, but no specific CVE, PoC, or KEV signal means no immediate patch action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for EDR bypass behavior and Linux rootkit indicators on web-facing servers; prioritize collecting relevant Linux endpoint telemetry if not already sourced, ahead of potential targeting expansion beyond current sectors.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Chinese-speaking cybercrime group targeting education, media, and tech sectors globally; useful for sector risk awareness and future board briefings, but no immediate vendor or regulatory action required based on available signals.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Defender's BTR.sys Driver Abused to Delete Security Tools at Boot</title><link>https://curasec.metacog.co.kr/insights/2026-08-22-microsoft-defender-s-own-driver-can-be-weaponized-to-delete/</link><pubDate>Sat, 22 Aug 2026 11:32:44 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-22-microsoft-defender-s-own-driver-can-be-weaponized-to-delete/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No exploitable flaw and no patch exists — this is abuse of a legitimately signed Defender component, so there&amp;rsquo;s nothing to patch; understand the technique and evaluate whether existing attack surface reduction or kernel driver allow-listing policies limit BTR.sys invocation outside Defender&amp;rsquo;s normal use.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Novel boot-time EDR-disablement technique worth building detections for: plan to hunt for anomalous BTR.sys loading events or unexpected security product file/registry removal at boot, and check whether your EDR vendor provides detection coverage for this abuse pattern.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Research disclosure with no active exploitation signals; relevant background if stakeholders ask about Defender&amp;rsquo;s reliability as a security control, but no leadership action is required at this time.&lt;/li>
&lt;/ul></description></item></channel></rss>