CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

They Got In Through SonicWall. Then They Tried to Kill | Huntress

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 759

As cited

Copy frozen at (site build).

threat intel

They Got In Through SonicWall. Then They Tried to Kill | Huntress

Huntress responded to an intrusion where attackers used compromised SonicWall VPN credentials and a revoked EnCase forensic driver to disable endpoint detection and response (EDR) processes through a bring-your-own-vulnerable-driver (BYOVD) attack. The incident demonstrates the attack chain from initial access through VPN compromise to EDR evasion. The attacker's ability to leverage legitimate-looking drivers highlights the sophistication of post-compromise techniques.

Why it matters: Security practitioners managing VPN access and EDR deployments need to monitor for compromised credentials on external-facing services and defend against unsigned or revoked drivers that can terminate security tooling.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

They Got In Through SonicWall. Then They Tried to Kill | Huntress

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

They Got In Through SonicWall. Then They Tried to Kill | Huntress

Attackers gained entry to a network by using compromised virtual private network (VPN) credentials from a SonicWall device. They then loaded a revoked EnCase forensic driver to terminate endpoint detection and response (EDR) processes via a bring-your-own-vulnerable-driver (BYOVD) attack. Huntress investigated the intrusion and responded to the incident.

Why it matters: Organizations that rely on SonicWall VPNs should audit credential security and monitor for attempts to load vulnerable drivers that could disable EDR.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

They Got In Through SonicWall. Then They Tried to Kill | Huntress

Attackers gained entry to a network by using compromised virtual private network (VPN) credentials from a SonicWall device. They then loaded a revoked EnCase forensic driver to terminate endpoint detection and response (EDR) processes via a bring-your-own-vulnerable-driver (BYOVD) attack. Huntress investigated the intrusion and responded to the incident.

Why it matters: Organizations that rely on SonicWall VPNs should audit credential security and monitor for attempts to load vulnerable drivers that could disable EDR.

VendorsSonicWall
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary