#EDR
The webcam story is a great tabletop prompt because it kills the "EDR everywhere" assumption. The real question: do you even have network visibility on those IoT segments — and who owns the incident when IT and facilities point at each other?
October 1, 2026 at 4:14 PM
@huntress.com
Attackers abuse Microsoft Defender exclusions and HideExclusionsFromLocalAdmins to evade scans and conceal changes.
-
IOCs: WhisperGate, GootKit, Muddled Libra
-
#EDR #ThreatIntel #Windows
Defender Exclusion Abuse
www.huntress.com
October 1, 2026 at 4:08 PM
ClickFix is the perfect social engineering primitive — it makes the victim paste the payload themselves, so there's no malicious download for EDR to catch. Sharing the C2 early is exactly right; the window between first report and takedown is when these IOCs save other orgs.
October 1, 2026 at 3:32 PM
Spicy but defensible. DNS sees everything before encryption and before the payload lands — C2, phishing, data exfil all need it. EDR wins on depth (memory, process trees), but if you can only have one sensor, the one sitting in front of every connection is the force multiplier.
October 1, 2026 at 3:27 PM
Before EDR and SIEM there was grep across file shares, and before that, watching netstat output like a hawk. The tools changed but the skill never did: knowing what normal looks like so the abnormal jumps out. That instinct is still the core of detection.
October 1, 2026 at 2:35 PM
最低限EDRを導入しろ(発狂)
October 1, 2026 at 12:21 PM
IIJ、SOCで正規アカウント悪用の検知を強化 – CrowdStrike ITPを活用
#IIJCSOCサービス #EDR運用オプション #ITニュース
ITちゃんねる
IIJ、SOCで正規アカウント悪用の検知を強化 – CrowdStrike ITPを活用 #IIJCSOCサービス #EDR運用オプション #ITニュース
it.f-frontier.com
October 1, 2026 at 11:09 AM
CYBER THREATS DON’T WAIT. WHY SHOULD YOUR SECURITY?

Protect your Windows & Mac business devices with VigiHunt

₹299 | 2 Years | Min. 10 Devices

Few hours left!

#CyberSecurity #BusinessSecurity #Antivirus #EDR #XDR #VigiHunt #B2B #DataSecurity #CyberThreats #EndpointSecurity
October 1, 2026 at 10:52 AM
Business cybersecurity at a special price!

Protect your Windows & Mac devices with VigiHunt

₹299 instead of ₹1,800

Min. 10 devices | 2 years

Limited-time offer!

WhatsApp: +91 87507 75884

#CyberSecurity #BusinessSecurity #Antivirus #EDR #XDR #B2B #DataSecurity #VigiHunt
October 1, 2026 at 10:28 AM
But Minnesota has *election-day* registration, so it is possible that some went through the registration process in the polling place, cast a ballot, and then had their registration rejected when it was processed post-election. What would you have the state government do to prevent that? End EDR?
October 1, 2026 at 8:47 AM
Has anyone looked at Sliver as a malware family? Useful for studying EDR evasions! Will have a report coming soon!
October 1, 2026 at 5:39 AM
2026年上半期サイバーセキュリティレポートを公開 高度化するEDRバイパス手法の実態やエージェント型AIがもたらす新たなリスクを解説 #PRTIMES (Sep 30)
prtimes.jp/main/html/rd...
2026年上半期サイバーセキュリティレポートを公開 高度化するEDRバイパス手法の実態やエージェント型AIがもたらす新たなリスクを解説
キヤノンマーケティングジャパン株式会社のプレスリリース(2026年9月30日 10時00分)2026年上半期サイバーセキュリティレポートを公開 高度化するEDRバイパス手法の実態やエージェント型AIがもたらす新たなリスクを解説
prtimes.jp
October 1, 2026 at 5:30 AM
新たなWindowsプロセスインジェクション手法、WriteProcessMemoryなしでEDRの監視をかいくぐる

新たに公開されたWindowsのプロセスインジェクション手法を使うと、厳重に監視されている WriteProcessMemory や VirtualAllocEx といったAPIを呼び出さずに、コンソールアプリケーション内にペイロードを配置して実行できます。 「コンソール名前付きパイプインジェクション」と名付けられた
新たなWindowsプロセスインジェクション手法、WriteProcessMemoryなしでEDRの監視をかいくぐる
新たに公開されたWindowsのプロセスインジェクション手法を使うと、厳重に監視されている WriteProcessMemory や VirtualAllocEx といったAPIを呼び出さずに、コンソールアプリケーション内にペイロードを配置して実行できます。 「コンソール名前付きパイプインジェクション」と名付けられた
blackhatnews.tokyo
October 1, 2026 at 3:17 AM
Buyer "caustic" is seeking corporate network access in the U.S., Canada, UK, EU, LATAM, and Australia, excluding government targets. Requested levels: Local Admin, Domain User, Domain Admin. #US #LATAM #UK
Corporate Access Buyer Seeks Privileged Network Entry Across U.S., Europe And LATAM
A buyer using the handle “caustic” is seeking corporate network access across the U.S., Canada, Australia, the UK, the EU, and LATAM, while excluding government targets. The post requests privileged access such as Local Admin, Domain User, or Domain Admin, and asks for details on host count, EDR/AV coverage, and any...
www.hendryadrian.com
October 1, 2026 at 3:16 AM
We've had this exact driver sample on LOLDrivers since Mar 20, 2026 (~6 months):
www.loldrivers.io/drivers/ed2...

Hash: 6e8b49cf70bf854e8c59c7d27cefa89406caf8978461190dabb86dafcd8554e1
PDFWKRNL.sys — LOLDrivers
AMD USB-C Power Delivery Firmware Update Kernel Library driver with arbitrary physical memory read/write capabilities. Identified in ESET EDR killers research (March 2026) as activ
www.loldrivers.io
September 30, 2026 at 9:01 PM
Lunex is using BYOVD to blind EDR, not just kill it.

Fake CAPTCHA → AMD PDFWKRNL.sys (CVE-2023-20598) → zeroes kernel callbacks → LunexStealer + sticky Native Messaging Host persistence.
September 30, 2026 at 9:01 PM
大风杀 (2025) 4K EDR

资源url:https://pan.quark.cn/s/208d277b44ef

海量资源频道:https://t.me/okpojie
海量资源网站:https://www.okpojie.com/
September 30, 2026 at 7:00 PM
No, no; don't sugar coat things. That is an accurate assessment of the situation.

It will make their lives easier too. EDR alerts dropped by like 80% when we deployed it (uBlock Origin, then lite), helpdesk calls for scareware all but stopped. Easily one of the highest ROI things they they can do.
September 30, 2026 at 6:26 PM