CuraSec

tag: Edr-Evasion · 2 items

2026-08-27 · The Hacker News · source ↗ #byovd#rat#edr-evasion
  • Engineer — Learn: The BYOVD technique exploiting a vulnerable OPSWAT driver to kill security tools is a notable evasion class worth understanding, but current targeting is regionally focused on Cambodia with no enrichment signals (no KEV, no PoC, no high EPSS) to justify immediate action in most environments.
  • SOC/IR — Plan: Build or tune detections for vulnerable OPSWAT driver loads and anomalous security-tool process terminations consistent with BYOVD; Spark RAT is open-source and signatures should be available to add to EDR and SIEM rule sets this quarter.
  • Leader — Skip
2026-08-14 · BleepingComputer · source ↗ #ransomware#edr-evasion#akira
  • Engineer — Plan: Verify your EDR agent is configured to load and protect in Safe Mode, and audit whether bcdedit or safeboot registry keys can be modified by non-admin processes — most EDR platforms have a specific setting for this that is not always on by default.
  • SOC/IR — Act: Hunt for bcdedit commands setting safeboot (T1562.001) and unexpected Safe Mode reboots in Windows event logs since Akira affiliates actively use this to blind EDR before data theft; tune alerts on bcdedit execution from unexpected parent processes.
  • Leader — Learn: Akira affiliates are successfully exfiltrating data even when encryption fails, confirming that ransomware incidents now carry extortion risk independent of operational disruption — worth a note in the next risk-register review.