Bring Your Own Installer EDR Bypass Observed in Ransomware Operation
ID: da7a62bf-71cf-5766-bafa-337a42d519f6
STIX ID: report--da7a62bf-71cf-5766-bafa-337a42d519f6
Feed Name: Halcyon Blog
**Bring Your Own Installer (BYOI) EDR bypass used in ransomware attacks:** Researchers observed attackers with administrative access forcibly terminate the vendor installer (msiexec.exe) during legitimate agent upgrades—after protections are shut down but before the new agent is deployed—to disable endpoint defenses and deploy ransomware; mitigation includes enabling an "Online Authorization" approval feature which was disabled by default in existing deployments but enabled by default for new installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
