Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms
Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms
Read Time:3 Minute, 30 Second

A security research experiment has demonstrated how a locally hosted, uncensored artificial-intelligence model can rapidly reshape credential-theft code to avoid endpoint defenses. In a controlled laboratory, the model modified a Windows LSASS dumping utility until it generated no alerts from the two endpoint detection and response products available to the researcher.

The result does not establish a universal technique for defeating EDR. The products were not named, their policies and configurations were not disclosed, and the test involved only two environments. Even with those limitations, the work offers a useful warning: open models running on local hardware can help an operator iterate on offensive code without sending prompts, binaries or source material to a monitored cloud service.

Why LSASS remains a valuable target

The Local Security Authority Subsystem Service plays a central role in Windows authentication. Its memory can contain credentials or other authentication material that an attacker with administrative or SYSTEM privileges may harvest and reuse for lateral movement. MITRE ATT&CK tracks LSASS memory dumping as T1003.001 under Credential Access.

Project Black researcher Eddie Zhang set a demanding benchmark: could an AI produce an executable that copied useful LSASS memory while remaining unnoticed by modern endpoint protection, with relatively little human direction? Several hosted models refused the request even though the research organization had approval under a cyber-verification program.

An open-weight DeepSeek model eventually produced a working program. According to the report, the executable accepted a process identifier, created a suspended reflected clone of the target, built a minidump in memory, encrypted it with XOR and wrote the result to disk. The researcher verified with pypykatz that the output could be parsed, but the initial binary still triggered EDR detections.

A local model changes the observable behavior

When the first model would not continue optimizing for stealth, the researcher moved the code to a community-modified Qwen model without the same guardrails. It ran locally on a system equipped with two Nvidia RTX 4090 graphics cards. A short request to make the tool more discreet produced a revision that avoided alerts on both lab EDR platforms.

Reviewing the new code revealed several practical changes. The model altered process-spawning behavior, requested narrower access rights against the target, added randomized pauses during dump construction, changed the output path and filename, and removed recognizable strings embedded in the binary.

These adjustments are important because endpoint tools often correlate several signals rather than looking only for one malicious file. Unusual process ancestry, high-privilege access to LSASS, known strings, dump creation and tightly sequenced actions can collectively expose credential theft. Altering multiple observables can make a familiar technique look different enough to evade a specific configuration.

What the experiment does—and does not—prove

The trial shows that a capable local model can reduce the time and specialist knowledge needed to customize known offensive code. It does not mean any attacker can automatically bypass every security product, nor does it show that the resulting tool would survive broader behavioral monitoring, network telemetry or a mature incident-response investigation.

Still, defenders should expect more tool variants tailored to individual environments. Static signatures and assumptions about recognizable public utilities will be less dependable when attackers can cheaply modify code structure, timing, strings and system calls through repeated local experimentation.

Layer protections around credential access

Organizations should treat EDR as one layer of defense rather than a guarantee. Reducing the number of users and processes capable of accessing LSASS can limit the opportunity before detection even becomes necessary.

  • Enable the LSASS credential-stealing attack-surface-reduction rule with tamper protection.
  • Run LSASS as a Protected Process Light and deploy Credential Guard where supported.
  • Remove unnecessary local administrator rights and separate privileged accounts.
  • Use unique credentials and restrict remote administrative access.
  • Monitor abnormal LSASS handle requests, memory dumps and suspicious file creation as a sequence.

The main lesson is not that endpoint security has become obsolete. It is that generative AI can accelerate an attacker’s feedback loop. Defenders need layered identity controls, behavior-based analytics and rapid isolation procedures that remain effective even when the malicious binary is new.

Source: Cyber Security News, published September 26, 2026.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms, use the discussion on Forum.

>> forum community

Comments

Leave a Reply