Free antivirus to kill EDRs
Description
It appears that some endpoint security solutions can be leveraged to disable other endpoint detection and response (EDR) products without generating any alerts, even when using a free trial environment
Steps
- Go to https://www.cisco.com/c/en/us/products/security/amp-for-endpoints/free-trial.html?utm_content=amp-free-trial and register for a free trial
- Install the agent on your target machine (requires local admin)
- In the console, navigate to Management > Policies
- Search for "Protect", and click the one for Windows
- Select the "Exclusions" tab, and remove all of them
- Next, identify the SHA256 of the EDR process you are targeting either on the host or through the Cisco console
- Navigate to "Outbreak Control" > "Blocked Application"
- Click edit on the "Blocked Application List"
- Enter the SHA256, and click "Add"
Reference: https://github.com/CroodSolutions/AutoRMM/tree/main/-%20EDR-on-EDR%20Violence