← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 14, 2026 · 13:36via Cyber Security News

Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware

Brief

A “Bring Your Own EDR” attack abuses trusted SentinelOne components to turn endpoint protection into a powerful malware shield. The research was presented at DEF CON 34 in Las Vegas, and SentinelOne fixed the reported issue in Agent version 26.

  • 1.

Endpoint detection and response tools operate with deep visibility and high privileges because they must inspect processes, files, memory, and system behavior.

Those same privileges can become dangerous when local interfaces, installer logic, and trust boundaries are not sufficiently protected.

The research focuses on Windows Protected Process Light, or PPL. This Windows security model is intended to prevent ordinary processes from reading, modifying, debugging, or terminating protected security services.

Antivirus and EDR products commonly use the Antimalware-Light protection level.

Read more on Cyber Security News