Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse
Akamai Technologies, Friday, August 7th, 2026
Akamai researchers show how a commercial EDR's own installer and COM interfaces can be turned into a PPL bypass and Trojan horse.
Akamai researchers demonstrate that legitimate SentinelOne EDR installer files and exposed COM interfaces can be abused to bypass Protected Process Light protections and run unsigned code without any kernel vulnerability.
The attack chains dumping protected processes via COM, extracting COM secrets from memory, and shellcode injection to gain execution inside PPL processes such as Windows Defender.
Management communications that rely on local DNS lookups can be blocked by editing the hosts file, isolating agents and disabling remote telemetry while the endpoint still appears protected.
Once compromised, EDR anti-tampering can be inverted so malicious payloads placed in EDR directories become untouchable by other processes.