Akamai researcher Shahak Morag demonstrated a 'Bring Your Own EDR' attack chain at DEF CON 34, abusing SentinelOne's exposed COM interfaces and installer validation to turn the EDR into a Trojan horse. By leveraging the SentinelHelper.1 COM object's Dump method, a local admin can dump any PPL-protected process, then chain this with PPLSystem to achieve unsigned code execution inside PPL processes such as Windows Defender. The attacker can install a rogue SentinelOne agent without a valid license, block management telemetry via local DNS manipulation, and use the EDR's own anti-tampering mechanisms to protect malicious payloads. The vulnerability was fixed in SentinelOne Agent version 26.1.1.
BYOEDR
1 post
Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse | Akamai