Four EDRs and no alerts: what are you left with
On 6 July, two SensePost researchers published a code injection technique and tested it against four market-leading EDRs configured to detect, block and remediate: it worked on all four and no alerts were created. On 22 September, Flashpoint reproduced it. The technique does not write into another process's memory —the path every EDR has watched for a decade— but instead places the payload into the parameters a new process starts with. We read both publications in full, including the part the headlines skipped: in Flashpoint's lab the XDR component DID block, and only stopped once two further evasions were stacked on top; and the authors themselves warn the technique "has multiple opportunities for detection". Also: why this is post-exploitation and not a way in, why the same primitive had already been described publicly before (with no known date), the four checks you can ask your console for this week —and the catch that none of them is a button, but a query over telemetry someone has to have kept and someone has to write—.