As cited
Copy frozen at (site build).
threat intel
They Got In Through SonicWall. Then They Tried to Kill | Huntress
Huntress responded to an intrusion where attackers used compromised SonicWall VPN credentials and a revoked EnCase forensic driver to disable endpoint detection and response (EDR) processes through a bring-your-own-vulnerable-driver (BYOVD) attack. The incident demonstrates the attack chain from initial access through VPN compromise to EDR evasion. The attacker's ability to leverage legitimate-looking drivers highlights the sophistication of post-compromise techniques.
Why it matters: Security practitioners managing VPN access and EDR deployments need to monitor for compromised credentials on external-facing services and defend against unsigned or revoked drivers that can terminate security tooling.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
They Got In Through SonicWall. Then They Tried to Kill | Huntress
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
They Got In Through SonicWall. Then They Tried to Kill | Huntress
Attackers gained entry to a network by using compromised virtual private network (VPN) credentials from a SonicWall device. They then loaded a revoked EnCase forensic driver to terminate endpoint detection and response (EDR) processes via a bring-your-own-vulnerable-driver (BYOVD) attack. Huntress investigated the intrusion and responded to the incident.
Why it matters: Organizations that rely on SonicWall VPNs should audit credential security and monitor for attempts to load vulnerable drivers that could disable EDR.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
They Got In Through SonicWall. Then They Tried to Kill | Huntress
Attackers gained entry to a network by using compromised virtual private network (VPN) credentials from a SonicWall device. They then loaded a revoked EnCase forensic driver to terminate endpoint detection and response (EDR) processes via a bring-your-own-vulnerable-driver (BYOVD) attack. Huntress investigated the intrusion and responded to the incident.
Why it matters: Organizations that rely on SonicWall VPNs should audit credential security and monitor for attempts to load vulnerable drivers that could disable EDR.
- Source published
- First seen by Cybersecurity Tracker