Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 341, Issue 1IT Vendor NewsAkamai Technologies

Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse

Akamai Technologies, Friday, August 7th, 2026

Akamai researchers show how a commercial EDR's own installer and COM interfaces can be turned into a PPL bypass and Trojan horse.

Akamai researchers demonstrate that legitimate SentinelOne EDR installer files and exposed COM interfaces can be abused to bypass Protected Process Light protections and run unsigned code without any kernel vulnerability.

The attack chains dumping protected processes via COM, extracting COM secrets from memory, and shellcode injection to gain execution inside PPL processes such as Windows Defender.

Management communications that rely on local DNS lookups can be blocked by editing the hosts file, isolating agents and disabling remote telemetry while the endpoint still appears protected.

Once compromised, EDR anti-tampering can be inverted so malicious payloads placed in EDR directories become untouchable by other processes.

more →  ·  More from Akamai Technologies →