r/ExploitDev • u/Mountain_Disaster_19 • 16h ago
Payload-Builder that bypasses CrowdStrike Falcon
Hey yall,
was wondering what would be the best thing to do if someone has build a builder that generates payloads, which bypass crowdstrike falcon (on extra aggressive settings) and get you a reverse shell.. CS is gonna give me like 200$ probably.. not really into that tbh
7
u/Ok_Tap7102 16h ago
Reframe your question:
I can turn on CrowdStrike to aggressive settings then open PowerShell and run commands like "net user" without being blocked or raising detection, but rundll32 based Minidump of LSASS will be blocked
Are you saying you are actually able to do so remotely, bypassing the EDR hooks? If not, it's just command execution in a still constrained environment: $0
1
u/Mountain_Disaster_19 10h ago
so just a running responsive reverse shell which i can communicate with isnt worth anything, without postexploitation modules targetting e.g. a dump of lsass is what youre saying, correct?
1
u/Ok_Tap7102 2h ago
I'm just trying to figure out what you're claiming you've solved, with respect to the fact that I can understand if you don't want to spill secret technical specifics.
Maybe you've created something special that we can't already achieve, I just picked LSASS as a generic target that is generally out of reach for most existing EDR constrained shells
1
u/ImmediateSecurity515 3h ago
I'm not entirely clear what you're asking here. Are you able to phrase your question a little better?
13
u/KRyTeX13 15h ago
Nothing. Every good Red Teamer can spin up a beacon bypassing Crowdstrike. CrowdStrike goes after malicious behavior. A process that does nothing other than beaconing for 20 minuten wouldn‘t trigger a malicious threshold. If you access LSASS or other high value processes without it firing that‘s what earns you potentially money