Skip to content
  • Categories
  • Recent
  • Tags
  • All Topics
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. BYOVD: Leveraging Raw Disk Reads to Bypass EDRInteresting write up on using vulnerable drivers to read the raw disk of a Windows system and extract files without ever touching those files directly.
Welcome to Caint!

Issues? Post in Comments & Feedback
You can now view, reply, and favourite posts from the Fediverse. You can click here or click on the on the navigation bar on the left.

BYOVD: Leveraging Raw Disk Reads to Bypass EDRInteresting write up on using vulnerable drivers to read the raw disk of a Windows system and extract files without ever touching those files directly.

Scheduled Pinned Locked Moved Uncategorized
cybersecurityinfosechackingmalwareredteam
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • DrewSecD This user is from outside of this forum
    DrewSecD This user is from outside of this forum
    DrewSec
    wrote last edited by
    #1

    BYOVD: Leveraging Raw Disk Reads to Bypass EDR

    Interesting write up on using vulnerable drivers to read the raw disk of a Windows system and extract files without ever touching those files directly. This subsequently allows the reading of sensitive files, such as the SAM.hive, SYSTEM.hive, and NTDS.dit, while also completely avoiding detection from EDR.

    #cybersecurity #infosec #hacking #malware #redteam

    https://medium.com/workday-engineering/leveraging-raw-disk-reads-to-bypass-edr-f145838b0e6d

    1 Reply Last reply
    1
    0
    • R AodeRelay shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • All Topics
    • Popular
    • World
    • Users
    • Groups