New BYOEDR Attack Exploits SentinelOne to Bypass Windows PPL Protections
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Security researchers have unveiled a new attack method known as 'Bring Your Own EDR' (BYOEDR) that leverages legitimate components of SentinelOne to bypass Windows Protected Process Light (PPL) protections. This technique allows the execution of unsigned code within highly secured processes, posing a significant risk to systems relying on SentinelOne for endpoint protection. The research was presented by Akamai at DEF CON 34 in Las Vegas. SentinelOne has since addressed the vulnerability in Agent version 26.1.1, mitigating the risk of exploitation. The attack highlights the potential for trusted security tools to be misused, turning them into shields for malware. The scope of impact includes organizations using SentinelOne, which operates with high privileges and deep visibility into endpoint activities. Immediate action is recommended for affected users to update their software to the latest version.
Key Points: • The BYOEDR attack exploits SentinelOne components to bypass Windows PPL protections. • The vulnerability was disclosed at DEF CON 34 and has been patched in Agent version 26.1.1. • Organizations using SentinelOne are at risk of unauthorized code execution within secured processes.