<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rayan Annabi on Senthorus Blog</title><link>https://blog.senthorus.ch/author/rayan-annabi/</link><description>Recent content in Rayan Annabi on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 22 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/rayan-annabi/index.xml" rel="self" type="application/rss+xml"/><item><title>Killing the Sensor First: What Happens Before the Encryptor Runs</title><link>https://blog.senthorus.ch/posts/edr_killers_byovd/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/edr_killers_byovd/</guid><description>&lt;img src="https://blog.senthorus.ch/edr_killers_byovd/edr_killers_byovd_0.png" alt="Featured image of post Killing the Sensor First: What Happens Before the Encryptor Runs" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>Read enough ransomware reports and you start noticing the same gap. Initial access is documented in detail. The encryptor is documented in detail. The minute in between, where the endpoint agent quietly stops talking, gets a single line.&lt;/p>
&lt;p>&lt;strong>That minute is where the intrusion is actually won.&lt;/strong>&lt;/p>
&lt;h2 id="the-stage-nobody-watches">The stage nobody watches
&lt;/h2>&lt;p>Once an operator has local admin on a host, encryption is rarely the next move. Blinding the sensor is. ESET describes EDR killers as a predictable, standard stage of modern ransomware operations, with attackers gaining high privileges first and then launching a killer to cripple endpoint defences before deploying the payload.&lt;/p>
&lt;p>For an MDR this changes how you read a quiet console. A client&amp;rsquo;s EDR going silent on three machines at once used to be filed under agent maintenance. In 2026 it deserves an escalation on its own merits, before anyone finds a ransom note.&lt;/p>
&lt;h2 id="why-a-signed-driver-works-so-well">Why a signed driver works so well
&lt;/h2>&lt;p>The technique behind most of these tools is BYOVD, &lt;code>bring your own vulnerable driver&lt;/code>. The goal is kernel-mode privileges, often called Ring 0, where code has unrestricted access to system memory and hardware. An attacker cannot load an unsigned malicious driver, so instead they bring one signed by a reputable vendor, typically a hardware manufacturer or an old antivirus version, that happens to carry a known vulnerability.&lt;/p>
&lt;p>Nothing is forged at any point. The drivers carry valid signatures from real vendors, which means Windows and most security products are predisposed to trust them. Nobody is cracking a certificate. They are simply loading an old, unpatched version of legitimate software that still contains a kernel level flaw, and old signed copies are trivially obtainable.&lt;/p>
&lt;p>Once execution lands at Ring 0, the attacker can terminate protected processes, tamper with kernel callbacks and switch off telemetry from underneath the layer the EDR operates in. This is also why tamper protection settings offer no comfort here. They run at user mode privilege level and cannot stop a tool that has already reached the kernel.&lt;/p>
&lt;h2 id="what-changed-over-the-last-eighteen-months">What changed over the last eighteen months
&lt;/h2>&lt;p>BYOVD stopped being an APT speciality somewhere in 2025 and became commodity tooling. ESET now counts almost 90 EDR killers in active use, 54 of them BYOVD based, abusing 35 distinct vulnerable drivers between them. Worth remembering when you read attribution reports: affiliates rather than core operators usually pick which killer to deploy, so the driver tells you very little about who is on the keyboard.&lt;/p>
&lt;p>Three things are worth pulling out of the 2026 research.&lt;/p>
&lt;p>The tooling now ships with the kit. ESET&amp;rsquo;s June 2026 investigation into the Gentlemen operation found that the operator centrally develops and maintains its own EDR killer framework, GentleKiller, and hands it to every affiliate as part of onboarding. The variants abuse drivers from Safetica, Zemana, Qihoo 360, IObit and Huawei.&lt;/p>
&lt;blockquote>
&lt;p>&lt;strong>&amp;ldquo;high operational effectiveness and tight integration&amp;rdquo;&lt;/strong>&lt;br>
&lt;em>Jakub Souček, ESET, on the Gentlemen toolkit&lt;/em>&lt;/p>&lt;/blockquote>
&lt;p>Blocklists are being outrun on purpose. Check Point documented more than 2,500 distinct variants of a single driver, &lt;code>TrueSight.sys&lt;/code>, produced by tweaking eight bytes in the PE header, each with a unique hash and a still valid signature. In an April 2026 intrusion, Expel found the attacker using &lt;code>ktapi.sys&lt;/code>, a Kontron industrial driver that was not on any public blocklist at the time.&lt;/p>
&lt;p>And the scale of some of this is genuinely uncomfortable. Cisco Talos published research in April 2026 showing that Qilin had built a technique capable of disabling more than 300 endpoint detection and response products.&lt;/p>
&lt;p>The category is also widening past drivers entirely. ESET identified script based tools that lean on built in commands like &lt;code>taskkill&lt;/code>, &lt;code>net stop&lt;/code> or &lt;code>sc delete&lt;/code>, with some variants combining scripting with Windows Safe Mode. Driverless options such as EDRSilencer and EDR-Freeze disrupt security tooling without touching the kernel at all.&lt;/p>
&lt;h2 id="where-the-chain-leaves-traces">Where the chain leaves traces
&lt;/h2>&lt;p>The sequence barely varies across families, which is the good news. Drop the driver, register it as a service, exploit it to reach Ring 0, then start killing processes. Each step maps to telemetry you already collect.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/edr_killers_byovd/edr_killers_byovd_1.png"
loading="lazy"
alt="BYOVD attack chain and the matching detection telemetry"
>&lt;/p>
&lt;p>Everything to the right of the exploit step is already too late. The detection value sits on the left.&lt;/p>
&lt;h2 id="four-places-to-look">Four places to look
&lt;/h2>&lt;p>Start with the driver landing on disk. It has to be written somewhere before it can load, so file creation monitoring against known vulnerable driver hashes gives you the earliest possible warning. The community maintained LOLDrivers database is the obvious feed for that.&lt;/p>
&lt;p>Then service creation. Loading a driver normally creates a kernel service, which puts Sysmon &lt;code>Event ID 13&lt;/code> on service registry keys and &lt;code>Event ID 6&lt;/code> on driver load at the centre of this. Rules that fire on a new driver being installed as a Windows service give you warning before the kill sequence starts.&lt;/p>
&lt;p>Third, Code Integrity logging. Under &lt;code>Applications and Services Logs &amp;gt; Microsoft &amp;gt; Windows &amp;gt; CodeIntegrity &amp;gt; Operational&lt;/code>, &lt;code>Event ID 3099&lt;/code> confirms which blocklist policy is genuinely active on a machine. Half the value here is discovering how much of your estate is not enforcing the policy you assumed it was.&lt;/p>
&lt;p>Fourth, and least practised, the silence itself. A gap in endpoint telemetry followed by evidence of malicious activity is a strong sign the EDR was disabled during that window. Agents that stop reporting, unexpected kernel driver installations in event logs and odd traffic picked up by network monitoring all point the same way.&lt;/p>
&lt;p>That last one deserves its own rule. Detection pipelines alert on events. Almost none of them alert on the absence of events. A rule that fires when an agent stops checking in, correlated against a recent service creation on the same host, costs very little to build and covers the exact scenario where every other control has been switched off.&lt;/p>
&lt;h2 id="hardening-and-its-ceiling">Hardening, and its ceiling
&lt;/h2>&lt;p>The controls that actually operate at or below the attack surface are HVCI, the Microsoft Vulnerable Driver Blocklist and detection on driver installation. HVCI verifies kernel code before execution and enforces the blocklist, and you can check it per device under Windows Security, Device Security, Core isolation. If Memory Integrity is greyed out, something is blocking it and that machine is worth a ticket.&lt;/p>
&lt;p>Alongside that, enable the ASR rule &amp;ldquo;Block abuse of exploited vulnerable signed drivers&amp;rdquo; so the driver never lands:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-powershell" data-lang="powershell">&lt;span style="display:flex;">&lt;span>Add-MpPreference `
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> -AttackSurfaceReductionRules_Ids 56a863a9-875e-&lt;span style="color:#ae81ff">4185&lt;/span>-98a7-b882c64b5ce5 `
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> -AttackSurfaceReductionRules_Actions Enabled
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Merge the driver block rules into a WDAC base policy on your most critical assets, deploy it in audit mode first, and keep local admin rights tight, since the whole chain assumes them.&lt;/p>
&lt;p>Be realistic about what this buys you. Blocklisting stops known vulnerable drivers, while capable operators rotate to signed drivers that are not on the list yet, or exploit flaws unknown to Microsoft and the EDR vendors, which bypasses enforcement entirely. There is movement on the platform side at least. By April 2026, Microsoft was reported to be removing trust for older cross signed kernel drivers in newer Windows releases, which could shrink the abusable surface considerably given how many LOLDrivers entries are cross signed.&lt;/p>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>An EDR killer is a line item in a ransomware as a service onboarding package now, not an exotic capability. Two things follow from that. Stop treating the endpoint agent as a trusted narrator and correlate it against identity, authentication and network telemetry that lives somewhere the attacker has not reached. And build the unglamorous detections, because by the time the encryptor runs, the best evidence you had was written twenty minutes earlier by a &lt;code>.sys&lt;/code> file nobody was watching.&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://www.eset.com/blog/en/business-topics/threat-landscape/what-are-edr-killers/" target="_blank" rel="noopener"
>ESET - What are EDR killers? How ransomware attacks disable EDR&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://thehackernews.com/2026/03/54-edr-killers-use-byovd-to-exploit-34.html" target="_blank" rel="noopener"
>The Hacker News - 54 EDR killers use BYOVD to exploit signed vulnerable drivers&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.techtimes.com/articles/318682/20260619/ransomware-gang-builds-its-own-edr-killer-byovd-arsenal-hits-478-victims.htm" target="_blank" rel="noopener"
>Ransomware gang builds its own EDR killer: the GentleKiller arsenal&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://guardsix.com/blog/byovd-how-signed-drivers-become-kernel-level-backdoors" target="_blank" rel="noopener"
>BYOVD: how signed drivers become kernel level backdoors&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.modernsecurity.nl/byovd-edr-killers-asr-wdac-hvci/" target="_blank" rel="noopener"
>BYOVD is back: how EDR killers ship inside RaaS kits and how to stop them&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.burgitech.com/blog/byovd-ransomware-bypass-endpoint-protection-2026" target="_blank" rel="noopener"
>BYOVD ransomware: how attackers bypass endpoint protection&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.veil-framework.com/byovd-bring-your-own-vulnerable-driver-the-latest-edr-killer-strategy/" target="_blank" rel="noopener"
>BYOVD detection surface and blind spots for detection engineering teams&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://aka.ms/VulnerableDriverBlockList" target="_blank" rel="noopener"
>Microsoft - Vulnerable Driver Blocklist&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>How APT Groups Evade Detection in a SOC</title><link>https://blog.senthorus.ch/posts/how_apt_groups_evade_detection/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/how_apt_groups_evade_detection/</guid><description>&lt;img src="https://blog.senthorus.ch/how_apt_groups_evade_detection/how_apt_groups_evade_detection_miniature.png" alt="Featured image of post How APT Groups Evade Detection in a SOC" />&lt;h1 id="how-apt-groups-evade-detection-in-a-soc">How APT Groups Evade Detection in a SOC
&lt;/h1>&lt;p>&lt;strong>Advanced Persistent Threats (APTs)&lt;/strong> represent some of the most sophisticated and dangerous cyber adversaries in the world. Unlike opportunistic attackers or commodity malware campaigns, APT groups are well-funded, highly skilled, and extremely patient. Their goal is not a quick win, it is long-term access, data exfiltration, or strategic disruption.&lt;/p>
&lt;p>For &lt;strong>Security Operations Centers (SOCs)&lt;/strong>, detecting APT activity is one of the hardest challenges. These attackers know how SOCs operate, and they deliberately design their techniques to blend in with normal network traffic, bypass standard detection tools, and remain unnoticed for months or even years.&lt;/p>
&lt;p>Let’s explore the primary ways APT groups evade detection in a SOC, and what defenders can do to counter them.&lt;/p>
&lt;hr>
&lt;p>&lt;img src="https://blog.senthorus.ch/how_apt_groups_evade_detection/how_apt_groups_evade_detection.png"
loading="lazy"
alt="Schema"
>&lt;/p>
&lt;h2 id="1-living-off-the-land-lolbins">1. Living Off the Land (LOLBins)
&lt;/h2>&lt;p>APT groups frequently abuse legitimate system tools, often called &lt;strong>Living-off-the-Land Binaries (LOLBins)&lt;/strong>. Instead of deploying custom malware that could be flagged by antivirus or EDR solutions, they use built-in utilities like:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>PowerShell&lt;/strong> – executing scripts and downloading payloads&lt;/li>
&lt;li>&lt;strong>WMI (Windows Management Instrumentation)&lt;/strong> – persistence and remote execution&lt;/li>
&lt;li>&lt;strong>Certutil&lt;/strong> – encoding/decoding and transferring files&lt;/li>
&lt;li>&lt;strong>Rundll32&lt;/strong> – running malicious code via DLLs&lt;/li>
&lt;/ul>
&lt;p>Because these tools are part of the operating system, their execution doesn’t immediately appear suspicious. To a SOC analyst looking at logs, activity may resemble normal administrative behavior.&lt;/p>
&lt;p>&lt;strong>Why it works:&lt;/strong> SOCs struggle to distinguish between legitimate admin activity and malicious abuse of system tools.&lt;/p>
&lt;hr>
&lt;h2 id="2-fileless-malware-and-memory-resident-payloads">2. Fileless Malware and Memory-Resident Payloads
&lt;/h2>&lt;p>Rather than writing malicious binaries to disk (where antivirus or EDR may detect them), APTs often operate entirely in memory. They inject code directly into legitimate processes or use scripting languages (like PowerShell or Python) to execute payloads dynamically.&lt;/p>
&lt;p>&lt;strong>Example:&lt;/strong>&lt;br>
&lt;em>APT29 (Cozy Bear)&lt;/em> has been observed using memory-resident implants that vanish once a system reboots, leaving almost no forensic trace.&lt;/p>
&lt;p>&lt;strong>Why it works:&lt;/strong> Traditional detection methods rely on scanning files on disk. Fileless techniques drastically reduce the footprint available for SOC tools to analyze.&lt;/p>
&lt;hr>
&lt;h2 id="3-encryption-and-traffic-obfuscation">3. Encryption and Traffic Obfuscation
&lt;/h2>&lt;p>Modern SOCs rely heavily on network monitoring to spot malicious traffic. APTs counter this by encrypting or disguising their communications.&lt;/p>
&lt;ul>
&lt;li>Using &lt;strong>HTTPS or TLS&lt;/strong> to hide command-and-control (C2) traffic inside normal web browsing patterns&lt;/li>
&lt;li>Leveraging &lt;strong>cloud services&lt;/strong> (e.g., Dropbox, Google Drive, OneDrive) as exfiltration channels&lt;/li>
&lt;li>&lt;strong>Domain fronting&lt;/strong>, where attackers hide C2 traffic behind trusted domains like Microsoft or Google&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Why it works:&lt;/strong> To a SOC, encrypted outbound traffic to cloud platforms looks identical to normal user activity. Without deep inspection, malicious traffic blends perfectly.&lt;/p>
&lt;hr>
&lt;h2 id="4-credential-theft-and-abuse">4. Credential Theft and Abuse
&lt;/h2>&lt;p>APTs often compromise &lt;strong>legitimate user accounts&lt;/strong> instead of creating new ones. Once they have valid credentials, they can move laterally, escalate privileges, and exfiltrate data, all under the guise of a trusted employee.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Pass-the-Hash&lt;/strong> or &lt;strong>Pass-the-Ticket&lt;/strong> attacks let them impersonate users without knowing their passwords&lt;/li>
&lt;li>&lt;strong>Privileged accounts&lt;/strong> (like domain admins) are especially targeted for stealthy persistence&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Why it works:&lt;/strong> SOC detection rules are often focused on failed logins, brute-force attempts, or unusual account creation. But if the attacker is using legitimate credentials, their activity can appear completely normal.&lt;/p>
&lt;hr>
&lt;h2 id="5-low-and-slow-tactics">5. Low-and-Slow Tactics
&lt;/h2>&lt;p>Unlike ransomware actors who create noise, APTs play the long game. They deliberately keep activity levels low to avoid triggering alerts.&lt;/p>
&lt;ul>
&lt;li>Exfiltrating data in &lt;strong>small chunks&lt;/strong> over weeks or months&lt;/li>
&lt;li>&lt;strong>Spacing out commands&lt;/strong> to avoid suspicious spikes in activity&lt;/li>
&lt;li>Operating during &lt;strong>regular business hours&lt;/strong> to blend in with normal network traffic&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Why it works:&lt;/strong> Most SOCs tune detection systems to identify abnormal spikes or bursts of malicious behavior. Slow, consistent activity often flies under the radar.&lt;/p>
&lt;hr>
&lt;h2 id="6-supply-chain-and-trusted-software-abuse">6. Supply Chain and Trusted Software Abuse
&lt;/h2>&lt;p>APT groups increasingly compromise &lt;strong>software vendors, IT providers, or managed services&lt;/strong> to infiltrate targets indirectly.&lt;br>
The &lt;strong>SolarWinds attack&lt;/strong> (attributed to &lt;em>APT29&lt;/em>) is a prime example: attackers compromised an update mechanism, pushing signed malicious code to thousands of customers.&lt;/p>
&lt;p>&lt;strong>Why it works:&lt;/strong> SOCs generally trust updates signed by legitimate vendors. Malicious behavior originating from a trusted source is extremely hard to flag without advanced behavioral monitoring.&lt;/p>
&lt;hr>
&lt;h2 id="7-evasion-of-detection-tools">7. Evasion of Detection Tools
&lt;/h2>&lt;p>APTs actively study SOC technologies like &lt;strong>SIEM, EDR, and AV&lt;/strong> to craft evasion strategies.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Log tampering:&lt;/strong> Clearing or modifying event logs to erase traces of activity&lt;/li>
&lt;li>&lt;strong>Process injection:&lt;/strong> Running code inside trusted processes (like &lt;em>explorer.exe&lt;/em> or &lt;em>svchost.exe&lt;/em>)&lt;/li>
&lt;li>&lt;strong>Disabling security tools:&lt;/strong> Shutting down EDR agents or tampering with Windows Event Logging&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Why it works:&lt;/strong> If the SOC’s visibility is reduced, analysts may miss critical parts of the attack chain.&lt;/p>
&lt;hr>
&lt;h2 id="8-insider-threats-and-social-engineering">8. Insider Threats and Social Engineering
&lt;/h2>&lt;p>Some APTs bypass technical detection entirely by exploiting the &lt;strong>human element&lt;/strong>.&lt;/p>
&lt;ul>
&lt;li>Recruiting insiders to provide credentials or disable monitoring&lt;/li>
&lt;li>Using &lt;strong>spear-phishing&lt;/strong> emails tailored so precisely they appear legitimate&lt;/li>
&lt;li>Deploying malware via &lt;strong>removable media&lt;/strong> or direct insider access&lt;/li>
&lt;/ul>
&lt;p>&lt;strong>Why it works:&lt;/strong> SOCs can defend against malicious code, but defending against a trusted employee acting maliciously is far more complex.&lt;/p>
&lt;hr>
&lt;h2 id="countermeasures-how-socs-can-respond">Countermeasures: How SOCs Can Respond
&lt;/h2>&lt;p>While APTs are formidable, they are not invisible. SOCs can strengthen detection with:&lt;/p>
&lt;ol>
&lt;li>&lt;strong>Behavioral Analytics&lt;/strong> – focus on deviations in user or system behavior rather than static signatures.&lt;/li>
&lt;li>&lt;strong>Threat Hunting&lt;/strong> – proactively search for anomalies in logs and endpoints instead of waiting for alerts.&lt;/li>
&lt;li>&lt;strong>Threat Intelligence Integration&lt;/strong> – use IOCs and TTPs from frameworks like &lt;strong>MITRE ATT&amp;amp;CK&lt;/strong> to spot attacker patterns.&lt;/li>
&lt;li>&lt;strong>Deception Technologies&lt;/strong> – deploy honeypots, honeytokens, or decoy accounts to lure attackers and reveal their presence.&lt;/li>
&lt;li>&lt;strong>Zero Trust Architecture&lt;/strong> – minimize reliance on implicit trust, even for internal accounts or services.&lt;/li>
&lt;li>&lt;strong>Continuous Training&lt;/strong> – upskill SOC analysts to recognize advanced techniques and not rely solely on automated alerts.&lt;/li>
&lt;/ol>
&lt;hr>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>APT groups evade SOC detection by mastering stealth: abusing legitimate tools, operating in memory, hiding traffic in encrypted channels, stealing credentials, and carefully pacing their operations. They study defenders as much as defenders study them.&lt;/p>
&lt;p>For SOC teams, the key lesson is that &lt;strong>prevention alone is not enough&lt;/strong>. Detection must evolve from static rules to &lt;strong>adaptive, intelligence-driven, and behavior-focused&lt;/strong> strategies.&lt;/p>
&lt;p>In the arms race between attackers and defenders, APTs thrive on invisibility. SOCs must respond by shining light in the darkest corners of their networks and staying vigilant against the threats designed to hide in plain sight.&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/advanced-persistent-threat-apt/" target="_blank" rel="noopener"
>Source 1&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.imperva.com/learn/application-security/apt-advanced-persistent-threat/" target="_blank" rel="noopener"
>Source 2&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cloud.google.com/security/resources/insights/apt-groups" target="_blank" rel="noopener"
>Source 3&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://pmc.ncbi.nlm.nih.gov/articles/PMC10336420/" target="_blank" rel="noopener"
>Source 4&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.darktrace.com/solutions/advanced-persistent-threats" target="_blank" rel="noopener"
>Source 5&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.cybermaxx.com/resources/intel-from-the-trenches-whats-happening-in-the-soc/" target="_blank" rel="noopener"
>Source 6&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://docs.rapid7.com/insightidr/apt-groups/" target="_blank" rel="noopener"
>Source 7&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://socradar.io/how-to-track-apt-groups-and-get-fresh-ioc-ttp/" target="_blank" rel="noopener"
>Source 8&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>Understanding CVE-2018-0171: A Persistent Threat to Network Infrastructure</title><link>https://blog.senthorus.ch/posts/cve_2018_0171/</link><pubDate>Wed, 29 Oct 2025 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/cve_2018_0171/</guid><description>&lt;img src="https://blog.senthorus.ch/CVE_2018_0171_miniature.png" alt="Featured image of post Understanding CVE-2018-0171: A Persistent Threat to Network Infrastructure" />&lt;h1 id="understanding-cve-2018-0171-a-persistent-threat-to-network-infrastructure">Understanding CVE-2018-0171: A Persistent Threat to Network Infrastructure
&lt;/h1>&lt;h2 id="1-the-nature-and-exploitation-of-cve-2018-0171">1. The Nature and Exploitation of CVE-2018-0171
&lt;/h2>&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2018_0171_cisco.png"
loading="lazy"
alt="CISCO"
>&lt;/p>
&lt;h3 id="11-what-is-cve-2018-0171">1.1 What Is CVE-2018-0171?
&lt;/h3>&lt;p>CVE-2018-0171 is a critical remote code execution (RCE) vulnerability affecting Cisco&amp;rsquo;s Smart Install feature, which is part of the IOS and IOS XE software platforms used in Cisco switches and routers. The flaw results from improper validation of packet data, allowing unauthenticated attackers to send specially crafted Smart Install messages over TCP port 4786.&lt;/p>
&lt;p>If successfully exploited, an attacker can trigger a buffer overflow, leading to denial-of-service (DoS) conditions or even full control over the affected device. The vulnerability received a CVSS v3 base score of 9.8, reflecting its critical severity.&lt;/p>
&lt;p>Smart Install was designed to simplify network deployment by automatically installing and configuring new switches without manual intervention. However, its default enablement on many devices inadvertently exposed networks to attack, especially when administrators were unaware of its risks (NVD).&lt;/p>
&lt;h3 id="12-how-the-vulnerability-is-exploited">1.2 How the Vulnerability Is Exploited
&lt;/h3>&lt;p>Exploitation of CVE-2018-0171 begins when an attacker identifies a vulnerable device on the network, often using simple scanning tools to detect open TCP port 4786. They then send crafted Smart Install packets designed to overflow memory buffers within the Smart Install client.&lt;/p>
&lt;p>&lt;strong>Consequences of successful exploitation include:&lt;/strong>&lt;/p>
&lt;ul>
&lt;li>Device crash or reload, resulting in temporary denial of service.&lt;/li>
&lt;li>Execution of arbitrary code, potentially giving attackers persistent access.&lt;/li>
&lt;li>Theft of sensitive configuration data, including routing tables, VLAN configurations, and administrative credentials.&lt;/li>
&lt;/ul>
&lt;p>The risk is particularly high because Smart Install is often enabled by default on many Cisco devices, meaning even a minimally secured network can be compromised without authentication. Older Cisco devices running software prior to IOS 12.2(52)SE are not affected because they lack the Smart Install feature (Proficio).&lt;/p>
&lt;h3 id="13-real-world-exploitation">1.3 Real-World Exploitation
&lt;/h3>&lt;p>Despite being disclosed in 2018, CVE-2018-0171 remains actively exploited. For instance, the Static Tundra group, a Russian state-sponsored cyber espionage operation, has repeatedly leveraged this vulnerability to infiltrate networks in multiple sectors: telecommunications, higher education, and manufacturing.&lt;/p>
&lt;p>Attackers typically use the vulnerability to:&lt;/p>
&lt;ul>
&lt;li>Steal configuration files, giving insight into network structure.&lt;/li>
&lt;li>Establish persistent access, allowing long-term surveillance.&lt;/li>
&lt;li>Move laterally within networks, potentially reaching sensitive systems.&lt;/li>
&lt;/ul>
&lt;p>Reports have confirmed that unpatched devices, particularly end-of-life switches and routers, remain the primary targets. This real-world activity demonstrates that legacy vulnerabilities can persist for years if not actively managed (Talos Intelligence, Splunk).&lt;/p>
&lt;h2 id="2-mitigation-and-defense-strategies">2. Mitigation and Defense Strategies
&lt;/h2>&lt;p>Protecting networks against CVE-2018-0171 requires a multi-layered approach, combining software updates, feature management, network segmentation, and continuous monitoring.&lt;/p>
&lt;h3 id="21-applying-ciscos-security-patches">2.1 Applying Cisco&amp;rsquo;s Security Patches
&lt;/h3>&lt;p>The most effective way to mitigate CVE-2018-0171 is by upgrading affected devices to patched software versions. Cisco has released updates for all impacted IOS and IOS XE releases.&lt;/p>
&lt;p>Administrators should use tools like the Cisco IOS Software Checker to:&lt;/p>
&lt;ul>
&lt;li>Identify vulnerable devices.&lt;/li>
&lt;li>Verify patch availability.&lt;/li>
&lt;li>Schedule updates during maintenance windows to minimize downtime.&lt;/li>
&lt;/ul>
&lt;p>Prompt patching prevents attackers from exploiting the vulnerability while maintaining network performance and security (Proficio).&lt;/p>
&lt;h3 id="22-disabling-the-smart-install-client-feature">2.2 Disabling the Smart Install Client Feature
&lt;/h3>&lt;p>If patching cannot be performed immediately, disabling the Smart Install client provides an effective interim mitigation. Disabling this feature ensures the device no longer listens on TCP port 4786, removing the attack vector.&lt;/p>
&lt;p>Cisco provides a safe procedure to disable Smart Install, which involves executing specific commands in the device configuration. While this may limit some automated deployment functionalities, it significantly reduces exposure until patches can be applied (Talos Intelligence).&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/CVE_2018_0171_schema.png"
loading="lazy"
alt="Schema CVE"
>&lt;/p>
&lt;h3 id="23-network-segmentation-and-monitoring">2.3 Network Segmentation and Monitoring
&lt;/h3>&lt;p>Beyond patching and feature management, network segmentation is critical. Segmentation separates critical infrastructure (e.g., core routers, data center switches) from less sensitive devices, reducing the risk of lateral movement by attackers.&lt;/p>
&lt;p>Additionally, continuous network monitoring allows early detection of malicious activity. Monitoring traffic on TCP port 4786 can reveal unauthorized attempts to exploit Smart Install, enabling rapid incident response before damage occurs.&lt;/p>
&lt;h3 id="24-regular-vulnerability-assessments">2.4 Regular Vulnerability Assessments
&lt;/h3>&lt;p>Ongoing vulnerability assessments are essential to maintaining a secure network environment. Regular scans identify devices with outdated firmware, misconfigurations, or enabled features that could be exploited.&lt;/p>
&lt;p>Organizations should also maintain an asset inventory to ensure all network devices are accounted for and updated. Automated tools like the Cisco IOS Software Checker or third-party vulnerability scanners can help streamline this process and reduce human error (Proficio).&lt;/p>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>CVE-2018-0171 continues to pose a significant threat to network infrastructure due to its high severity and persistent exploitation by advanced threat actors.&lt;/p>
&lt;p>&lt;strong>Mitigation requires a multi-layered approach:&lt;/strong>&lt;/p>
&lt;ol>
&lt;li>Apply software patches immediately.&lt;/li>
&lt;li>Disable unnecessary features like Smart Install.&lt;/li>
&lt;li>Segment networks to contain potential compromises.&lt;/li>
&lt;li>Continuously monitor and assess vulnerabilities.&lt;/li>
&lt;/ol>
&lt;p>By combining proactive patching, strict feature management, network monitoring, and regular assessments, organizations can minimize the risk of exploitation and protect critical network assets. Vigilance, ongoing maintenance, and rapid response remain the best defenses against legacy vulnerabilities like CVE-2018-0171.&lt;/p>
&lt;h2 id="sources">Sources
&lt;/h2>&lt;ol>
&lt;li>&lt;a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2018-0171" target="_blank" rel="noopener"
>Source 1&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180419-smartinstall" target="_blank" rel="noopener"
>Source 2&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.talosintelligence.com/" target="_blank" rel="noopener"
>Source 3&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.proficio.com/resources/security-advisories/cisco-smart-install" target="_blank" rel="noopener"
>Source 4&lt;/a>&lt;/li>
&lt;/ol></description></item><item><title>The Log4Shell Vulnerability</title><link>https://blog.senthorus.ch/posts/the_log4shell_vulnerability/</link><pubDate>Sun, 26 Nov 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/the_log4shell_vulnerability/</guid><description>&lt;img src="https://blog.senthorus.ch/the_log4shell_vulnerability/The_Log4Shell_Vulnerability0.png" alt="Featured image of post The Log4Shell Vulnerability" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>Log4Shell refers to a software weakness found in Apache Log4j 2, a widely used Java library used to log error messages in software applications. This vulnerability, identified as CVE-2021-44228, allows a malicious remote attacker to gain control over an internet-connected device running specific versions of Log4j 2.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/the_log4shell_vulnerability/The_Log4Shell_Vulnerability1.png"
loading="lazy"
alt="Log4j logo"
>&lt;/p>
&lt;p>A researcher from the Alibaba Cloud team reported the vulnerability on November 24, 2021, and Apache publicly disclosed it on December 9, 2021. This is a significant problem because it affects an extensive range of devices, numbering in the hundreds of millions.&lt;/p>
&lt;p>This vulnerability can be abused by attackers through text messages to remotely manipulate a computer. Due to the ease with which it can be exploited, this vulnerability has been given the highest possible severity score (10/10).&lt;/p>
&lt;h2 id="part-1-understanding-the-vulnerability">Part 1: Understanding the Vulnerability
&lt;/h2>&lt;h3 id="a-log4shell-mechanism">a. Log4Shell Mechanism
&lt;/h3>&lt;p>Log4j2 comes with a built-in feature called &amp;lsquo;Message Lookup Substitution.&amp;rsquo; This functionality allows specific strings to be swapped, during the logging process, with dynamically generated strings.&lt;/p>
&lt;p>The vulnerability arises from a feature called JNDI (Java Naming and Directory Interface) lookup, which allows Log4j configurations to reference external resources like LDAP servers. This feature allows a designated Java class to be retrieved from a remote location and deserialized, thus executing part of the class code. In this way, the attacker can obtain remote code execution on the application.&lt;/p>
&lt;p>Here’s a schema which shows the attack flow of Log4Shell using an LDAP server:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/the_log4shell_vulnerability/The_Log4Shell_Vulnerability2.png"
loading="lazy"
alt="Log4j Attack Explanation"
>&lt;/p>
&lt;p>Source: &lt;a class="link" href="https://cloud-one-security.awsworkshop.io/50_protection_demo/07_log4shell.html" target="_blank" rel="noopener"
>Cloud One Security Workshop&lt;/a>&lt;/p>
&lt;p>&lt;strong>Step-by-step explication:&lt;/strong>&lt;/p>
&lt;ul>
&lt;li>The attacker scans the Internet looking for exposed Log4j vulnerable applications.&lt;/li>
&lt;li>The attacker sends the crafted log entry to the target application&amp;rsquo;s log system via a web form or API request.&lt;/li>
&lt;li>When the target application logs the malicious entry, Apache Log4j 2 parses the log entry and processes it. If the Log4j version is vulnerable and the payload is successful, Log4j will query the remote LDAP server (or another resource specified in the payload).&lt;/li>
&lt;li>The LDAP server will respond to the query with a malicious payload containing a malicious Java class.&lt;/li>
&lt;li>The victim&amp;rsquo;s server will download and execute the malicious payload, and the attacker will, for example, have a remote shell on the victim&amp;rsquo;s server.&lt;/li>
&lt;/ul>
&lt;p>For more insights or hands-on experience, the platform TryHackMe offers a room called &lt;a class="link" href="https://tryhackme.com/room/solar" target="_blank" rel="noopener"
>‘Solar, exploiting log4j’&lt;/a> with a detailed Proof of Concept.&lt;/p>
&lt;h3 id="b-potential-impacts">b. Potential Impacts
&lt;/h3>&lt;p>Log4Shell has had a huge impact on organizations worldwide. Once exploited, it allows the attacker complete remote access and control over the device. A successful attack may result in:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Data exfiltration&lt;/strong>: Attackers can steal sensitive data from affected devices.&lt;/li>
&lt;li>&lt;strong>Financial consequences&lt;/strong>: According to &lt;a class="link" href="https://www.atatus.com/blog/log4shell-vulnerability/" target="_blank" rel="noopener"
>Atatus&lt;/a>, remediation costs can reach approximately $33,000.&lt;/li>
&lt;li>&lt;strong>System Compromise&lt;/strong>: Can lead to complete compromise of systems and networks.&lt;/li>
&lt;li>&lt;strong>Reputational damage&lt;/strong>: Public breaches can erode customer trust and affect revenue.&lt;/li>
&lt;/ul>
&lt;h2 id="part-2-reaction-and-solutions">Part 2: Reaction and Solutions
&lt;/h2>&lt;h3 id="c-community-response">c. Community Response
&lt;/h3>&lt;p>The cybersecurity community responded swiftly. Security experts, developers, and organizations assessed systems and collaborated on mitigation.&lt;/p>
&lt;p>A notable example is a &lt;a class="link" href="https://github.com/authomize/log4j-log4shell-affected" target="_blank" rel="noopener"
>GitHub repository&lt;/a> listing affected components, apps, and vendors.&lt;/p>
&lt;p>Community collaboration helped share tools, patches, and vital information to secure systems.&lt;/p>
&lt;h3 id="d-detection--mitigation">d. Detection &amp;amp; Mitigation
&lt;/h3>&lt;p>&lt;strong>Detection&lt;/strong>:&lt;/p>
&lt;p>Determine where Log4j is used and whether the versions are vulnerable. You can use YARA rules to scan for Log4Shell exploitation attempts. One such rule is available &lt;a class="link" href="https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar" target="_blank" rel="noopener"
>here&lt;/a>.&lt;/p>
&lt;p>&lt;strong>If assets are potentially affected, isolate them&lt;/strong>:&lt;/p>
&lt;ul>
&lt;li>Physically remove from the network&lt;/li>
&lt;li>Move to a “jail VLAN”&lt;/li>
&lt;li>Block at the network layer&lt;/li>
&lt;li>Implement strict firewall rules&lt;/li>
&lt;li>Restrict communication to the internet and the enterprise network&lt;/li>
&lt;/ul>
&lt;p>All Log4j versions up to and including 2.16.0 are vulnerable. Upgrade to version 2.17.0 or higher.&lt;/p>
&lt;p>If an upgrade isn’t possible, disable the JNDI feature in the &lt;code>log4j2.xml&lt;/code> or &lt;code>log4j2.properties&lt;/code>:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-xml" data-lang="xml">&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">&amp;lt;Configuration&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;Properties&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;Property&lt;/span> &lt;span style="color:#a6e22e">name=&lt;/span>&lt;span style="color:#e6db74">&amp;#34;log4j2.formatMsgNoLookups&amp;#34;&lt;/span>&lt;span style="color:#f92672">&amp;gt;&lt;/span>true&lt;span style="color:#f92672">&amp;lt;/Property&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> &lt;span style="color:#f92672">&amp;lt;/Properties&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#f92672">&amp;lt;/Configuration&amp;gt;&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Additionally, use firewall rules to limit access to Log4j services. Whitelist trusted IP addresses and block others.&lt;/p>
&lt;p>Continue to hunt for compromise indicators and initiate Incident Response if needed.&lt;/p>
&lt;h2 id="conclusion">Conclusion
&lt;/h2>&lt;p>The Log4Shell vulnerability (CVE-2021-44228) is a critical cybersecurity issue that allows remote code execution through flaws in Apache Log4j 2.&lt;/p>
&lt;p>It stems from &amp;lsquo;Message Lookup Substitution&amp;rsquo; and JNDI features, and its exploitation can lead to severe consequences, including data breaches, system compromises, and financial losses.&lt;/p>
&lt;p>The cybersecurity community responded quickly with collaboration, patches, and shared resources. Mitigation includes detection, isolation, updates, configuration changes, and network restrictions.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://www.atatus.com/blog/log4shell-vulnerability/" target="_blank" rel="noopener"
>Atatus: Log4Shell Vulnerability&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.dynatrace.com/news/blog/what-is-log4shell/" target="_blank" rel="noopener"
>Dynatrace: What is Log4Shell?&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://inonst.medium.com/log4shell-simple-techincal-explanation-of-the-exploit-a5a3dd1918ec" target="_blank" rel="noopener"
>Medium: Technical Explanation&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://phoenix.security/the-impact-of-log4shell-vulnerability/" target="_blank" rel="noopener"
>Phoenix Security: Impact&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://cloud-one-security.awsworkshop.io/50_protection_demo/07_log4shell.html" target="_blank" rel="noopener"
>Cloud One Security Workshop&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.techtarget.com/searchsecurity/tip/How-to-mitigate-Log4Shell-the-Log4j-vulnerability" target="_blank" rel="noopener"
>TechTarget: Mitigation Guide&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a" target="_blank" rel="noopener"
>CISA Advisory&lt;/a>&lt;/li>
&lt;/ul></description></item></channel></rss>