HomeSecurityNew EDR bypass "Bring Your Own Installer" used in ransomware attacks

New EDR bypass “Bring Your Own Installer” used in ransomware attacks

A new EDR bypass technique called “ Bring Your Own Installer ” is being used in attacks to bypass SentinelOne ’s tamper protection feature , allowing attackers to disable endpoint detection and response (EDR) agents and install the Babuk ransomware .

See also: Hackers use Eye Pyramid Tool to develop malware

EDR ransomware bypass

This technique exploits a loophole in the agent upgrade process, which allows attackers to terminate active EDR agents, leaving devices unprotected.

The attack was discovered by John Ailes and Tim Mashni of Aon's Stroz Friedberg Incident Response team after a client was hit by ransomware earlier this year. The technique does not rely on third-party tools or drivers , as is typically the case with EDR bypasses, but instead exploits the SentinelOne installer itself.

SentinelOne recommends that customers enable the “Online Authorization” setting, which is disabled by default, to prevent this attack.

Stroz Friedberg researchers explain that SentinelOne protects its EDR agent with an anti-tamper protection feature, which requires either manual action via the SentinelOne management console or the entry of a unique password to uninstall the agent.

However, as with many software installers, when installing a different version of the agent, the SentinelOne installer terminates any related Windows just before replacing existing files with the new version.

See also: Hackers target SentinelOne infrastructure and customers

Attackers discovered that they could exploit this short window of opportunity by running a legitimate SentinelOne installer and then forcibly aborting the installation process once the agent services were terminated, leaving the devices unprotected.

New EDR bypass "Bring Your Own Installer" used in ransomware attacks
New EDR bypass “Bring Your Own Installer” used in ransomware attacks

Earlier this year, Stroz Friedberg took on the investigation of an attack on a customer network, with logs showing that the attackers gained administrative access through a vulnerability in the customer’s system. The attackers then used this new bypass technique, terminating the SentinelOne Windows installation process (“msiexec.exe”) before the new agent version was installed and activated. With device protection disabled, they were able to install the ransomware.

Speaking to BleepingComputer, Ailes said that attackers can use either older or newer versions of the agent for the attack, meaning that even if devices are running the latest version, they remain vulnerable.

Stroz Friedberg responsibly disclosed this attack to SentinelOne, which in turn communicated private countermeasures to its customers in January 2025.

The recommended measure is to enable the “Online Authorization” feature in Sentinel’s policy settings, which, when enabled, requires approval via the management console before any local agent upgrade, downgrade, or uninstallation can occur. SentinelOne has also shared Stroz Friedberg’s notice of this new technique with other major EDR solution providers, in case they are also affected.

See also: Abuse of Zoom's remote control feature to steal crypto

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What is particularly important to note is that these types of attacks do not rely on sophisticated or specialized third-party tools , but rather on the misuse of official and authoritative tools from the manufacturer, such as the SentinelOne installer. This tactic — also known as living-off-the-land — makes detection and prevention much more difficult, as legitimate processes are used that do not immediately raise suspicion.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS