InfoGuard Labs

17 posts

InfoGuard Labs banner
InfoGuard Labs

InfoGuard Labs

@InfoGuard_Labs

Insights from the frontlines of offensive security and incident response @ https://t.co/uMKNWv9KUy

Katılım Aralık 2024
1 Takip Edilen237 Takipçiler
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
If you can read the detection rules, evading them becomes a lot easier. New write-up on decrypting Cortex XDR behavioral rules and abusing Global Whitelists by @p0w1_. TL;DR: just put ':\Windows\ccmcache' in your command line. Fixed in Agent 9.1. labs.infoguard.ch/posts/decrypti…
English
0
22
59
3.9K
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
Abusing Cortex XDR Live Terminal as C2 We reverse-engineered the IR payload and found ways to route EDR traffic to attacker-controlled tenants or custom servers. Living off the Land #LOTL with EDRs. Full write-up by @p0w1_ 👇labs.infoguard.ch/posts/abusing_…
English
0
26
61
5.7K
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
Need a SYSTEM shell? Just ask your EDR! CVE-2025-13176: ESET Inspect Connector looks for an OpenSSL config in a user-writable path. It’s an easy LPE that loads your payload directly into the EDR process. by @p0w1_ labs.infoguard.ch/advisories/cve…
English
1
29
97
8.5K
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
We noticed some misunderstandings about the described vulnerabilities. We've updated the blog post with a clearer summary of the attacks and added a new attack chart to show the attack flow. The attacks directly target the Defender cloud endpoints. They can be executed without being on the targeted host after obtaining the machine ID. labs.infoguard.ch/posts/attackin…
English
0
0
1
134
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
New blog post by @p0w1_ : We looked into Microsoft Defender for Endpoint's cloud communication and found multiple vulnerabilities. Want to intercept isolation requests as an unauthenticated attacker? Or upload hidden malware to IR? MSRC: low severity 🤷 labs.infoguard.ch/posts/attackin…
English
3
37
89
13.7K
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
We've published technical details and a PoC exploit for CVE-2025-47187 and CVE-2025-47188 – two vulnerabilities in Mitel SIP Phones that lead to unauthenticated RCE: labs.infoguard.ch/posts/cve-2025…
English
1
3
11
628
InfoGuard Labs
InfoGuard Labs@InfoGuard_Labs·
New blog post: Fuzzing Microsoft Defender's mpengine.dll using snapshot fuzzing (WTF, kAFL/NYX). We uncovered several out-of-bounds read & null dereference bugs that can crash the main Defender process on a file scan. Details -> labs.infoguard.ch/posts/attackin…
English
3
75
189
10.6K