Bring Your Own EDR Attack Weaponizes SentinelOne to Bypass Windows Security
Brief
A newly demonstrated “ Bring Your Own EDR ” attack can turn a legitimate SentinelOne endpoint agent into a privileged Trojan horse on Windows.
Documented by Akamai, the technique abuses exposed administrative interfaces and trust relationships within the EDR stack to access Protected Process Light (PPL) processes and to execute unsigned code without a kernel exploit or a vulnerable driver.
Presented at DEF CON 34 , the findings highlight a troublesome reality for defenders: endpoint security tools operate with exceptional privilege, making insecure local interfaces and weak installation assumptions unusually high-impact attack surfaces.
Bring Your Own EDR Attack Weaponizes SentinelOne
Akamai said the reported SentinelOne issue was fixed in Agent version 26.
- 1.
