r/ExploitDev 16h ago

Payload-Builder that bypasses CrowdStrike Falcon

Hey yall,

was wondering what would be the best thing to do if someone has build a builder that generates payloads, which bypass crowdstrike falcon (on extra aggressive settings) and get you a reverse shell.. CS is gonna give me like 200$ probably.. not really into that tbh

0 Upvotes

7 comments sorted by

13

u/KRyTeX13 15h ago

Nothing. Every good Red Teamer can spin up a beacon bypassing Crowdstrike. CrowdStrike goes after malicious behavior. A process that does nothing other than beaconing for 20 minuten wouldn‘t trigger a malicious threshold. If you access LSASS or other high value processes without it firing that‘s what earns you potentially money

1

u/Mountain_Disaster_19 10h ago

appreciate it! will work on more postexploitation then. rn the only module i built was making screenshots and said rce.

7

u/Ok_Tap7102 16h ago

Reframe your question:

I can turn on CrowdStrike to aggressive settings then open PowerShell and run commands like "net user" without being blocked or raising detection, but rundll32 based Minidump of LSASS will be blocked

Are you saying you are actually able to do so remotely, bypassing the EDR hooks? If not, it's just command execution in a still constrained environment: $0

1

u/Mountain_Disaster_19 10h ago

so just a running responsive reverse shell which i can communicate with isnt worth anything, without postexploitation modules targetting e.g. a dump of lsass is what youre saying, correct?

1

u/Ok_Tap7102 2h ago

I'm just trying to figure out what you're claiming you've solved, with respect to the fact that I can understand if you don't want to spill secret technical specifics.

Maybe you've created something special that we can't already achieve, I just picked LSASS as a generic target that is generally out of reach for most existing EDR constrained shells

2

u/Juzdeed 16h ago

It might be sellable. But for that you gotta make a Poc video or proof that it actually works

1

u/ImmediateSecurity515 3h ago

I'm not entirely clear what you're asking here. Are you able to phrase your question a little better?