Evil XDR: Researcher Turns Palo Alto Software Into Perfect Malware

General News

Summary

A creative exploit of Palo Alto Networks extended detection and response (XDR) software could have allowed attackers to puppet it like a malicious multitool. In a briefing at Black Hat Asia on April 17, Shmuel Cohen, security researcher at SafeBreach, described how he not only reverse-engineered and cracked into the companys signature Cortex product but also weaponized it to deploy a reverse shell and ransomware. For instance, to perform real-time monitoring and threat detection across IT ecosystems, XDR demands the highest possible permissions, and access to very sensitive information. After taking complete control in his proof of concept attack, Cohen recalls, "What I did first was change the protection password on the XDR so it cannot be removed. There was one vulnerability in his attack chain, however, that they chose to leave as is: the fact that Cortexs Lua files are stored entirely in plaintext, with no encryption whatsoever, despite their highly sensitive nature.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
No AI classifications detected

Linked Companies