Using Memory Analysis to Detect EDR-Nullifying Malware
ID: c203b600-607d-55c4-9775-5d026085fded
STIX ID: report--c203b600-607d-55c4-9775-5d026085fded
Feed Name: Volexity Blog
This Volexity analysis describes AVBurner, a kernel-space evasion tool tied to an APT (SnakeCharmer/Earth Longzhi) that disables EDR/AV process-creation callbacks by using a vulnerable driver (RTCore64.sys) to patch the PspCreateProcessNotifyRoutine callback array; the report explains the internals of the Windows callback mechanism, demonstrates detection via Volatility 3 and Volexity Volcano, lists IOCs (including targeted SYS metadata and the vulnerable driver), and recommends monitoring for BYOVD drivers and applying Microsoft driver-block mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
