New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly secured processes. This research, presented by Akamai at DEF CON 34, demonstrates how trusted endpoint detection and response (EDR) software can […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
