Tech
Screen displaying AI chat interface DeepSeek on a dark background.
Photo: Matheus Bertelli

AI Model Rewrites Windows Credential Dumper to Slip Past EDRs in Lab Test

A locally hosted AI model altered a Windows credential‑dumping tool to evade two endpoint detection products in a lab, showing generative AI can speed offensive tool creation.

In a controlled laboratory environment, an uncensored, locally hosted artificial‑intelligence model was used to modify a Windows credential‑dumping utility, enabling it to bypass detection by two Endpoint Detection and Response (EDR) products.

The experiment was documented by Project Black researcher Eddie Zhang, who targeted the Local Security Authority Subsystem Service (LSASS) memory as the dump source, demonstrating the model’s capability to adapt offensive software.

ALSO READ | US Moves to Ban Chinese Advanced Robots Over Espionage Risks, Builds Own AI Infrastructure

Zhang’s findings underscore that readily accessible generative AI can accelerate the development of custom offensive tools, raising concerns for defenders about the speed at which such evasion techniques can be produced.

Video: AASLR: Getting Started with Atomic Red Team | Carrie Roberts
Watch on YouTube ↗
Why This Matters

The demonstration shows that even modest AI resources can be weaponized to defeat endpoint security, forcing security teams to anticipate faster‑evolving evasion methods and to reinforce detection strategies against AI‑generated threats.

Reporting based on verified dispatches from Cybersecuritynews. View primary release ↗
Stay Connected
Follow SamacharDaily on Instagram

Visual explainers, infographics, and daily news briefings on your feed.

More in Tech