Preview image for a blog post

UAT-10147 Unveils SPECTRE: A Cross-Platform EDR-Evasive Kernel-Level Threat

SPECTRE implant: cross-platform C2, process injection, credential theft, EDR bypass, Linux rootkit, BYOVD capabilities.
Preview image for a blog post

Qilin & Warlock Ransomware: Unmasking BYOVD Tactics to Silence EDRs and Evade Detection

Qilin and Warlock ransomware exploit vulnerable drivers (BYOVD) to disable over 300 EDR tools, achieving kernel-level persistence and evasion.
Preview image for a blog post

Reynolds Ransomware: Kernel-Mode Evasion with Embedded BYOVD Driver for Unprecedented EDR Disablement

Reynolds Ransomware embeds a BYOVD driver to achieve kernel-mode privilege escalation and disable EDR, posing a critical threat.