EDR bypassing has become a technique of choice for threat actors and has enabled a market of tools being sold on cybercrime forums:
* Unit42 uncovered a variant of EDRSandBlast being sold on XSS and Exploit.
* CheckPoint Research uncovered the use of a vulnerable driver, Truesight.sys, which evaded the Microsoft