<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #EDR Evasion</title><description>Cybersecurity articles tagged #EDR Evasion on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>UAT-10147 Leverages Agentic AI for EDR-Evasive Cybercrime</title><link>https://runtimerebel.com/blog/uat-10147-leverages-agentic-ai-for-edr-evasive-cybercrime</link><guid isPermaLink="true">https://runtimerebel.com/blog/uat-10147-leverages-agentic-ai-for-edr-evasive-cybercrime</guid><description>Talos details UAT-10147, an AI-driven cybercrime group orchestrating sophisticated post-compromise operations and evading EDR with custom rootkits.</description><pubDate>Fri, 21 Aug 2026 00:46:37 GMT</pubDate><category>Agentic AI</category><category>Cybercrime</category><category>EDR Evasion</category><category>UAT 10147</category><category>SPECTRE Implant</category></item><item><title>Windows Bind Link Evasion: How to Detect Malware Hiding from EDR</title><link>https://runtimerebel.com/blog/windows-bind-link-evasion-how-to-detect-malware-hiding-from-edr</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-bind-link-evasion-how-to-detect-malware-hiding-from-edr</guid><description>Bitdefender researchers reveal how Windows bind links create filesystem discrepancies to bypass security tools. Learn how to mitigate this evasion technique.</description><pubDate>Wed, 15 Jul 2026 13:48:18 GMT</pubDate><category>Windows Security</category><category>Bind Link</category><category>EDR Evasion</category><category>Bitdefender</category><category>Filesystem Attacks</category></item><item><title>GodDamn Ransomware Leverages Signed Driver to Disable EDR</title><link>https://runtimerebel.com/blog/goddamn-ransomware-leverages-signed-driver-to-disable-edr</link><guid isPermaLink="true">https://runtimerebel.com/blog/goddamn-ransomware-leverages-signed-driver-to-disable-edr</guid><description>Analysis of GodDamn ransomware&apos;s BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.</description><pubDate>Thu, 09 Jul 2026 11:03:47 GMT</pubDate><category>GodDamn Ransomware</category><category>BYOVD</category><category>Kernel Driver</category><category>EDR Evasion</category><category>Microsoft Signed Driver</category><category>Ransomware</category></item><item><title>Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies</title><link>https://runtimerebel.com/blog/gentlemen-ransomware-edr-evasion-tactics-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/gentlemen-ransomware-edr-evasion-tactics-and-mitigation-strategies</guid><description>Runtime Rebel details Gentlemen ransomware&apos;s advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.</description><pubDate>Fri, 19 Jun 2026 01:11:06 GMT</pubDate><category>Gentlemen Ransomware</category><category>RaaS</category><category>EDR Evasion</category><category>Endpoint Security</category><category>Malware</category></item><item><title>Attackers Automate EDR Evasion Testing with Python Scripts</title><link>https://runtimerebel.com/blog/attackers-automate-edr-evasion-testing-with-python-scripts</link><guid isPermaLink="true">https://runtimerebel.com/blog/attackers-automate-edr-evasion-testing-with-python-scripts</guid><description>Attackers are automating EDR evasion testing using Python scripts against major platforms like Sophos, CrowdStrike, and Windows Defender, challenging defenses.</description><pubDate>Thu, 04 Jun 2026 01:09:53 GMT</pubDate><category>EDR Evasion</category><category>Sophos</category><category>CrowdStrike</category><category>Windows Defender</category><category>Python Scripts</category><category>Automation</category><category>Threat Intelligence</category></item><item><title>AI-Built Ransomware Toolkit Automates EDR Evasion, AD Discovery</title><link>https://runtimerebel.com/blog/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery</guid><description>New AI-powered ransomware toolkit automates Active Directory discovery and EDR evasion, posing advanced threats. Learn its capabilities and mitigation strategies.</description><pubDate>Tue, 02 Jun 2026 21:09:58 GMT</pubDate><category>Ransomware</category><category>AI</category><category>EDR Evasion</category><category>Active Directory</category><category>Toolkit</category><category>Threat Intelligence</category></item><item><title>Malware Evolution: How New Libraries and Languages Bypass EDR</title><link>https://runtimerebel.com/blog/malware-evolution-how-new-libraries-and-languages-bypass-edr</link><guid isPermaLink="true">https://runtimerebel.com/blog/malware-evolution-how-new-libraries-and-languages-bypass-edr</guid><description>Attackers are adopting Go, Rust, and custom libraries to evade static signatures. Learn how to adapt your detection engineering for modern malware binaries.</description><pubDate>Fri, 15 May 2026 09:13:34 GMT</pubDate><category>Malware Development</category><category>EDR Evasion</category><category>Go Malware</category><category>Rust Malware</category><category>Detection Engineering</category></item><item><title>Payouts King Ransomware Deploys QEMU VMs to Evade EDR Solutions</title><link>https://runtimerebel.com/blog/payouts-king-ransomware-deploys-qemu-vms-to-evade-edr-solutions</link><guid isPermaLink="true">https://runtimerebel.com/blog/payouts-king-ransomware-deploys-qemu-vms-to-evade-edr-solutions</guid><description>Payouts King ransomware leverages QEMU virtualization and reverse SSH tunnels to bypass endpoint security and encrypt MSSQL servers on corporate networks.</description><pubDate>Fri, 17 Apr 2026 20:18:46 GMT</pubDate><category>Payouts King</category><category>QEMU</category><category>EDR Evasion</category><category>Ransomware</category><category>MSSQL</category></item><item><title>Warlock Ransomware: BYOVD Techniques and Post-Exploitation Analysis</title><link>https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/warlock-ransomware-byovd-techniques-and-post-exploitation-analysis</guid><description>The Warlock ransomware group has evolved its tactics, utilizing BYOVD techniques and stealthy cross-network activity to bypass EDR and security controls.</description><pubDate>Tue, 17 Mar 2026 16:31:42 GMT</pubDate><category>Warlock Ransomware</category><category>BYOVD</category><category>EDR Evasion</category><category>Lateral Movement</category><category>Post Exploitation</category></item><item><title>Hypervisor-Based Persistence: Abusing Virtual Machines for Stealth</title><link>https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</link><guid isPermaLink="true">https://runtimerebel.com/blog/hypervisor-based-persistence-abusing-virtual-machines-for-stealth</guid><description>Analysis of how threat actors leverage virtualization platforms to host malicious guest OSs, bypassing host-level EDR and maintaining persistent access.</description><pubDate>Thu, 26 Feb 2026 04:39:45 GMT</pubDate><category>Persistence Mechanisms</category><category>EDR Evasion</category><category>Virtualization Abuse</category><category>Threat Hunting</category><category>SANS ISC</category></item></channel></rss>