I bet this plays havoc with the vast majority of EDRs. I can think of a few ways to go about detecting this, I look forward to the defensive counter blog posthttps://twitter.com/_batsec_/status/1405491567369101316 …
-
-
Replying to @dwizzzleMSFT
Isn’t this just a PE loader that also links the library in to the PEB? Most reflective losers don’t do that since it is less sneaky but other then that it looks pretty similar (especially from a detection standpoint)
2 replies 0 retweets 12 likes -
Replying to @JosephBialek
I dunno if this actually less sneaky if your going to use Images from disk since a reflective loader would still cause a bunch of CreateFile(). In practice EDRs have a terrible time disambiguating legit JIT from reflective and this approach makes that more practical to use imo
1 reply 0 retweets 1 like
Ive already told him how to run exe files with the content being generated programmatic as read without actually ever touching disk. Guess its first in next release then....
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.