# Endpoint Security & XDR

Cybersecurity practices and tools for protecting computing endpoints and consolidating detection and response across endpoint, network, and other security telemetry.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic

DevFeed: [The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic](<https://devfeed.tech/articles/the-only-perfect-endpoint-prevention-and-response-epr-score-in-2026-belongs-to-elastic-26916.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/av-comparatives-epr-test-2026>)

Author: Mia LaVada

Published: 2026-09-15T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Security](<https://devfeed.tech/topics/security.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [alert-fatigue](<https://devfeed.tech/tags/alert-fatigue.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [investigation-incident-response-security-compliance-security-analytics-xdr](<https://devfeed.tech/tags/investigation-incident-response-security-compliance-security-analytics-xdr.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [protection](<https://devfeed.tech/tags/protection.md>), [security](<https://devfeed.tech/tags/security.md>), [security-endpoint-security](<https://devfeed.tech/tags/security-endpoint-security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [testing](<https://devfeed.tech/tags/testing.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

Elastic describes its results in the 2026 AV-Comparatives Endpoint Prevention and Response test, reporting 100% protection scores, zero false alerts, and the lowest modeled operational footprint among tested products. The article explains that Elastic stopped all 50 attack scenarios at the initial phase.

### Source excerpt

Elastic sits at the very top of this year's AV-Comparatives' CyberRisk Quadrant within the 2026 Endpoint Prevention and Response (EPR) test with the highest protection scores at 100%. Learn more.

## CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

DevFeed: [CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks](<https://devfeed.tech/articles/crowdstrike-extends-endpoint-security-to-stop-software-supply-chain-attacks-8305.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks/>)

Author: Anne Aarness - Chris Prall

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [codex](<https://devfeed.tech/tags/codex.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [endpoint-security-xdr](<https://devfeed.tech/tags/endpoint-security-xdr.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-packages](<https://devfeed.tech/tags/open-source-packages.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article describes CrowdStrike's Real-Time Supply Chain Attack Protection, embedded in the Falcon sensor, which detects and blocks malicious open-source packages before their code executes on enterprise endpoints. It explains how AI-assisted and agentic applications have expanded software supply chain risk beyond developer workstations to endpoints across the organization.

### Source excerpt

Real-Time Supply Chain Attack Protection, embedded into the Falcon sensor, blocks malicious open-source packages at download to protect the endpoint.

## The hidden work of modernizing Malwarebytes

DevFeed: [The hidden work of modernizing Malwarebytes](<https://devfeed.tech/articles/the-hidden-work-of-modernizing-malwarebytes-8434.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/inside-malwarebytes/2026/09/the-hidden-work-of-modernizing-malwarebytes>)

Author: Anna Tukhtarova

Published: 2026-09-04T17:15:42Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>)

Tags: [diagnostics](<https://devfeed.tech/tags/diagnostics.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [inside-malwarebytes](<https://devfeed.tech/tags/inside-malwarebytes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [net](<https://devfeed.tech/tags/net.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains Malwarebytes' migration of its managed Windows components to .NET 10 and why runtime and dependency upgrades require security-feature-level rigor in endpoint software.

### Source excerpt

Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

## Counterfeit installers to system compromise: Tracking a deceptive software download campaign

DevFeed: [Counterfeit installers to system compromise: Tracking a deceptive software download campaign](<https://devfeed.tech/articles/counterfeit-installers-to-system-compromise-tracking-a-deceptive-software-download-campaign-7637.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/>)

Author: Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar

Published: 2026-09-01T22:48:28Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [china](<https://devfeed.tech/tags/china.md>), [defender](<https://devfeed.tech/tags/defender.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft documents an active malware campaign that uses counterfeit software-download pages and malicious installers to compromise systems. It outlines the attack chain, Defender XDR detection and disruption, and mitigations for blocking untrusted downloads and strengthening endpoint protections.

### Source excerpt

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.

## The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

DevFeed: [The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](<https://devfeed.tech/articles/the-state-of-ai-enabled-malware-august-2026-from-brand-abuse-to-agentic-execution-7744.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/>)

Author: Sara McBroom

Published: 2026-08-25T10:00:57Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [dataset](<https://devfeed.tech/topics/dataset.md>), [data](<https://devfeed.tech/topics/data.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [article](<https://devfeed.tech/tags/article.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [code](<https://devfeed.tech/tags/code.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [data](<https://devfeed.tech/tags/data.md>), [dll-hijacking](<https://devfeed.tech/tags/dll-hijacking.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Unit 42 analyzes 405 malware samples incorporating AI through mechanisms such as brand impersonation, LLM-generated code, and agentic execution loops. The research finds that most samples remain proof-of-concept or sandbox activity, while existing behavioral detection, cloud sandboxing, and endpoint analytics can detect the threats that reach operational environments.

### Source excerpt

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

## Bring your security stack into Edge for Business -- with support for more partners

DevFeed: [Bring your security stack into Edge for Business -- with support for more partners](<https://devfeed.tech/articles/bring-your-security-stack-into-edge-for-business-with-support-for-more-partners-4250.md>)

Original publisher: [Read original article](<https://blogs.windows.com/msedgedev/2026/08/04/bring-your-security-stack-into-edge-for-business-with-support-for-more-partners/>)

Author: Microsoft Edge Team

Published: 2026-08-04T16:00:24Z

Content type: article

Language: en

Sources: [Microsoft Edge Blog](<https://devfeed.tech/sources/microsoft-edge-blog.md>)

Topics: [Edge for Business](<https://devfeed.tech/topics/edge-for-business.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Cisco Secure Access](<https://devfeed.tech/topics/cisco-secure-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [edge-for-business](<https://devfeed.tech/tags/edge-for-business.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This Microsoft Edge Blog article announces expanded Edge for Business security connector integrations. It highlights Cisco Secure Access, Tanium, and Clever integrations for browser-based security, telemetry, endpoint visibility, compliance validation, data protection, AI guardrails, and streamlined MFA in education environments.

### Source excerpt

At a glance Edge for Business security connectors extend your security tools into the browser, so you gain visibility and enforcement where work happens. This update adds new partner integrations, including Cisco Secure Access, The post Bring your security stack into Edge for Business -- with support for more partners appeared first on Microsoft Edge Blog.

## ESET Threat Report H1 2026

DevFeed: [ESET Threat Report H1 2026](<https://devfeed.tech/articles/eset-threat-report-h1-2026-8365.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/>)

Author: Jiří Kropáč

Published: 2026-07-08T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [code](<https://devfeed.tech/tags/code.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H1 2026 threat report describes attackers adapting established techniques across new platforms and behaviors. It highlights the expanding abuse of AI skills, PromptSpy Android malware using Google Gemini, the spread of ClickFix and QR-code phishing, and continued ransomware activity involving EDR killers.

### Source excerpt

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

## Killing me gently: Inside Gentlemen's EDR killer framework

DevFeed: [Killing me gently: Inside Gentlemen's EDR killer framework](<https://devfeed.tech/articles/killing-me-gently-inside-gentlemen-s-edr-killer-framework-8373.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/>)

Author: Jakub Souček

Published: 2026-06-18T09:46:32Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [insights](<https://devfeed.tech/tags/insights.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [southeast-asia](<https://devfeed.tech/tags/southeast-asia.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

ESET Research analyzes Gentlemen's ransomware-as-a-service operation and its portfolio of EDR-killing tools. The article examines the in-house GentleKiller framework, third-party tools, shared defense-evasion techniques, and the group's rapid adoption of BYOVD exploits, using incident-level visibility and leaked internal data.

### Source excerpt

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

## Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows

DevFeed: [Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows](<https://devfeed.tech/articles/bloodhound-windows-23068.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1027132/>)

Author: StepVolg ("Лаборатория Касперского")

Published: 2026-04-24T12:37:53Z

Content type: tutorial

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [bloodhound](<https://devfeed.tech/tags/bloodhound.md>), [enumerate](<https://devfeed.tech/tags/enumerate.md>), [red-teaming](<https://devfeed.tech/tags/red-teaming.md>), [sharphound](<https://devfeed.tech/tags/sharphound.md>), [siem](<https://devfeed.tech/tags/siem.md>), [soc](<https://devfeed.tech/tags/soc.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-1ad1db2b7e3a](<https://devfeed.tech/tags/windows-1ad1db2b7e3a.md>)

### AI overview

The article examines traces left by BloodHound collectors in Windows logs and discusses detecting Active Directory reconnaissance activity.

### Source excerpt

Служба каталогов Active Directory остается одной из самых популярных целей как среди злоумышленников, так и среди специалистов по Red Teaming и пентестеров. С выходом новых версий операционных систем семейства Windows продолжают появляться новые векторы атак на AD, например атаки на Delegated Managed Service Accounts (dMSA) в 2025-м. В ходе каждой атаки есть этап сбора информации, обнаружение которого является более сложной задачей, чем кажется на первый взгляд. Согласно аналитическому отчету нашего сервиса MDR за 2025 год в целом обнаружение данного этапа атак затруднено из-за большого количества ложных срабатываний, что снижает качество обнаружения и уменьшает вероятность предотвращения атаки, особенно в больших инфраструктурах с тысячами активов. Меня зовут Степан Ляхов, я работаю старшим инженером SOC в "Лаборатории Касперского". В этой статье я хочу рассмотреть один из самых популярных инструментов для сбора информации о домене Active Directory, разобрать, какие следы он оставляет в журналах и как обнаружить его активность. Читать далее

## EDR killers explained: Beyond the drivers

DevFeed: [EDR killers explained: Beyond the drivers](<https://devfeed.tech/articles/edr-killers-explained-beyond-the-drivers-8361.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/>)

Author: Jakub Souček

Published: 2026-03-19T09:55:08Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [development](<https://devfeed.tech/tags/development.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

ESET researchers analyze nearly 90 EDR killers used in real ransomware intrusions, examining vulnerable-driver, anti-rootkit, script-based, and driverless approaches to disabling endpoint protection. The article explains how affiliates select and adapt these tools, why driver-based attribution can mislead, and how commercialized kits increase defense complexity.

### Source excerpt

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

## Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece

DevFeed: [Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece](<https://devfeed.tech/articles/seeking-symmetry-during-att-ck-season-how-to-harness-today-s-diverse-analyst-and-tester-landscape-to-paint-a-security-masterpiece-8340.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/seeking-symmetry-attck-season-harness-todays-diverse-analyst-tester-landscape-paint-security-masterpiece/>)

Author: Márk Szabó James Shepperd Ben Tudor

Published: 2025-12-10T15:03:51Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [incident](<https://devfeed.tech/tags/incident.md>), [industry](<https://devfeed.tech/tags/industry.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [practitioner](<https://devfeed.tech/tags/practitioner.md>), [report](<https://devfeed.tech/tags/report.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article explains how security practitioners can interpret and connect cybersecurity reports and tests from analyst firms and independent testing labs. It focuses on endpoint security, including product evaluations, feature testing, broader market analyses, and assessments against known advanced adversary attacks, to support more informed protection-stack and purchasing decisions.

### Source excerpt

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

## Designing for security and usability: Figma's modern endpoint strategy

DevFeed: [Designing for security and usability: Figma's modern endpoint strategy](<https://devfeed.tech/articles/designing-for-security-and-usability-figma-s-modern-endpoint-strategy-9715.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/figmas-modern-endpoint-strategy/>)

Author: Lamarr Henry

Published: 2025-04-04T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>), [Usability](<https://devfeed.tech/topics/usability.md>), [User experience (UX)](<https://devfeed.tech/topics/ux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>), [ux](<https://devfeed.tech/tags/ux.md>)

### AI overview

Figma describes an endpoint security strategy designed around usability. Its Endpoint Security Baseline uses controls such as browser updates, disabled remote login, and prevention of kernel extensions to protect corporate devices while keeping security self-serve and minimizing employee friction.

### Source excerpt

At Figma, security doesn't have to slow you down. We've designed our corporate endpoint security with UX in mind, making it seamless and self-serve.

## What caused 8.5 million Windows computers to crash in the CrowdStrike Falcon incident

DevFeed: [What caused 8.5 million Windows computers to crash in the CrowdStrike Falcon incident](<https://devfeed.tech/articles/here-s-what-really-caused-8-5-million-computers-to-crash-17967.md>)

Original publisher: [Read original article](<https://newsletter.betterstack.com/p/heres-what-really-caused-85-million>)

Author: Richard Oliver Bray

Published: 2024-08-28T13:00:58Z

Content type: article

Language: en

Sources: [Hacking Scale by Better Stack](<https://devfeed.tech/sources/hacking-scale-by-better-stack.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>)

Tags: [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains how a CrowdStrike Falcon software issue caused 8.5 million Windows machines to crash on July 19, 2024. It describes Falcon's endpoint-security architecture, including cloud servers, machine-learning analysis, threat intelligence, and kernel-level sensors.

### Source excerpt

How one security product crippled the world because of bad programming

## Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion (Part 2)

DevFeed: [Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion (Part 2)](<https://devfeed.tech/articles/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-part-2-20505.md>)

Original publisher: [Read original article](<https://bohops.com/2022/08/22/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-part-2/>)

Author: bohops

Published: 2022-08-22T23:48:27Z

Content type: article

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [code](<https://devfeed.tech/tags/code.md>), [events](<https://devfeed.tech/tags/events.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [net](<https://devfeed.tech/tags/net.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [processes](<https://devfeed.tech/tags/processes.md>), [research](<https://devfeed.tech/tags/research.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This article revisits .NET CLR Usage Logs and examines two additional tampering techniques that can prevent log creation, including discretionary ACL blocking. It also discusses how monitoring Usage Log creation events can help identify suspicious processes that loaded the .NET CLR.

### Source excerpt

Introduction Last year, I blogged about Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion. In that part 1 post, we covered: Recently, I revisited the research topic to close the loop on some outstanding research and figured I would share. In this post, we'll recap .NET Usage Logs, highlight two other tampering techniques, [...]

## Unmanaged Code Execution with .NET Dynamic PInvoke

DevFeed: [Unmanaged Code Execution with .NET Dynamic PInvoke](<https://devfeed.tech/articles/unmanaged-code-execution-with-net-dynamic-pinvoke-20504.md>)

Original publisher: [Read original article](<https://bohops.com/2022/04/02/unmanaged-code-execution-with-net-dynamic-pinvoke/>)

Author: bohops

Published: 2022-04-02T16:45:49Z

Content type: tutorial

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [Code](<https://devfeed.tech/topics/code.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>)

Tags: [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [code](<https://devfeed.tech/tags/code.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [interop](<https://devfeed.tech/tags/interop.md>), [native](<https://devfeed.tech/tags/native.md>), [net](<https://devfeed.tech/tags/net.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This developer article explains classic P/Invoke in .NET and introduces Dynamic PInvoke, a technique for calling and executing native code differently from managed code. It discusses limitations, .NET executable structure, and possible defensive-evasion implications.

### Source excerpt

Yes, you read that correctly - "Dynamic Pinvoke" as in "Dynamic Platform Invoke" Background Recently, I was browsing through Microsoft documentation and other blogs to gain a better understanding of .NET dynamic types and objects. I've always found the topic very interesting mainly due to its relative obscurity and the offensive opportunities for defensive evasion. [...]

## Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion

DevFeed: [Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion](<https://devfeed.tech/articles/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-20500.md>)

Original publisher: [Read original article](<https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/>)

Author: bohops

Published: 2021-03-16T04:08:58Z

Content type: article

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [.NET](<https://devfeed.tech/topics/net.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [logging](<https://devfeed.tech/tags/logging.md>), [net](<https://devfeed.tech/tags/net.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This article examines how .NET CLR Usage Logs can help defenders detect and investigate .NET execution, including assembly injection into process memory. It describes how the CLR creates Usage Log files and discusses tampering techniques intended to evade endpoint detection, along with monitoring opportunities for identifying that tampering.

### Source excerpt

Introduction In recent years, there have been numerous published techniques for evading endpoint security solutions and sources such as A/V, EDR and logging facilities. The methods deployed to achieve the desired result usually differ in sophistication and implementation, however, effectiveness is usually the end goal (of course, with thoughtful consideration of potential tradeoffs). Defenders can [...]

## EDR Bypass Methods: Blending In, Unhooking, and Direct Syscalls

DevFeed: [EDR Bypass Methods: Blending In, Unhooking, and Direct Syscalls](<https://devfeed.tech/articles/lets-create-an-edr-and-bypass-it-part-2-32630.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/>)

Author: CCob

Published: 2020-06-14T10:47:09Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Code](<https://devfeed.tech/topics/code.md>), [API](<https://devfeed.tech/topics/api.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [antivirus](<https://devfeed.tech/tags/antivirus.md>), [api](<https://devfeed.tech/tags/api.md>), [av](<https://devfeed.tech/tags/av.md>), [boilerplate](<https://devfeed.tech/tags/boilerplate.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [cobalt-strike](<https://devfeed.tech/tags/cobalt-strike.md>), [code](<https://devfeed.tech/tags/code.md>), [edr](<https://devfeed.tech/tags/edr.md>), [hooking](<https://devfeed.tech/tags/hooking.md>), [process](<https://devfeed.tech/tags/process.md>), [sharpblock](<https://devfeed.tech/tags/sharpblock.md>), [trampoline](<https://devfeed.tech/tags/trampoline.md>)

### AI overview

This tutorial examines methods for bypassing an active-protection EDR, including avoiding suspicious RWX memory changes, unhooking API calls, and using direct syscall instructions. It also introduces SharpBlock and accompanying code.

### Source excerpt

A 2 part series on creating a basic EDR detection system and then a bypass implementation. In part 2 I introduce SharpBlock, a method of bypassing EDR's. The post Lets Create An EDR... And Bypass It! Part 2 appeared first on Ethical Chaos.

## Creating a Basic EDR: Detection Methods and Sandbox Bypass Concepts (Part 1)

DevFeed: [Creating a Basic EDR: Detection Methods and Sandbox Bypass Concepts (Part 1)](<https://devfeed.tech/articles/lets-create-an-edr-and-bypass-it-part-1-32629.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2020/05/27/lets-create-an-edr-and-bypass-it-part-1/>)

Author: CCob

Published: 2020-05-27T18:50:50Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [antivirus](<https://devfeed.tech/tags/antivirus.md>), [api](<https://devfeed.tech/tags/api.md>), [av](<https://devfeed.tech/tags/av.md>), [binaries](<https://devfeed.tech/tags/binaries.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [edr](<https://devfeed.tech/tags/edr.md>), [hooking](<https://devfeed.tech/tags/hooking.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [malware](<https://devfeed.tech/tags/malware.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [trampoline](<https://devfeed.tech/tags/trampoline.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Part one explains how a basic EDR detects malicious files and behavior through signature detection, kernel-level file system filters, sandboxing, and dynamic analysis. It also introduces sandbox bypass concepts involving analysis time limits and disrupted control flow.

### Source excerpt

A 2 part series on creating a basic EDR detection system and then a bypass implementation. In part one we cover how to create a basic EDR. The post Lets Create An EDR... And Bypass It! Part 1 appeared first on Ethical Chaos.