Ransomware Attack Bypasses EDR with BYOI Technique
ID: 76a3a42a-9b2a-5f7e-9f9a-64297d480545
STIX ID: report--76a3a42a-9b2a-5f7e-9f9a-64297d480545
Feed Name: Halcyon Blog
Threat Score
**Executive summary:** Researchers uncovered a "Bring Your Own Installer" technique that abuses SentinelOne's agent upgrade process—killing msiexec.exe mid-install—to take hosts offline in the SentinelOne console and permit deployment of Babuk ransomware; SentinelOne issued mitigation guidance to enable "Online Authorization," but many environments remained vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
