BSides Canberra 2025

Ding Dong The EDR is DEAD
2025-09-26 , Main Track

Endpoint Detection and Response (EDR) is the watchdog running on your endpoint to detect and respond to threats in real-time. However, like other defenses, it is not a foolproof solution. In this talk we present a recent attack on a current EDR product (Palo Alto Cortex XDR) resulting in a bug bounty ($2k) winning CVE-2024-8690.

Ayman is a principal security consultant at CyberCX with a decade of professional cybersecurity experience. Ayman enjoys offensive security research, vulnerability discovery and malware analysis.