TGViewer
Proxy Bar Proxy Bar @proxy_bar · 21.5K subscribers
Post #3312 8.13K
Signed to Kill: Reverse Engineering a 0-Day Used to Disable CrowdStrike EDR

Original text by Jehad Abudagga

The article presents a reverse-engineering analysis of a kernel driver used in a BYOVD (Bring Your Own Vulnerable Driver) attack to disable security software, including CrowdStrike Falcon EDR. The researcher discovered multiple variants of a Microsoft-signed driver that expose a dangerous IOCTL interface capable of terminating arbitrary processes. Because the…

https://core-jmp.org/2026/04/signed-to-kill-reverse-engineering-a-0-day-used-to-disable-crowdstrike-edr/
  • 👍 14
  • 🔥 3
More from @proxy_bar
  1. Sep 28, 2026CVE-2026-19444: kubectl 😆😆😆
  2. Sep 28, 2026Prompt Injection in the Wild
  3. Sep 24, 2026Вспомнилось ! Был такой хороший гайд Introduction to Exploit Development Сегодня он интере…
  4. Sep 23, 2026Linux container escape * PoC
  5. Sep 21, 2026Идея для "быстрых свиданий" Ну это те, которые 5 минут общаешься, потом пересаживаетесь. З…
  6. Sep 20, 2026А скиньте фотки с тусы а )))
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →