Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
A local uncensored Qwen model revised an LSASS dumper until two lab EDRs no longer detected it.
Project Black researcher Eddie Zhang reported that a locally hosted, uncensored Qwen 3.8 27B model revised a Windows LSASS credential dumper until two unnamed lab EDR products generated no detections. Hosted Claude models refused the task, while DeepSeek v4 Flash 0731 produced an initial dump that still alerted and then applied a safety guardrail. The result is limited: EDR vendors and configurations were not published, and lab success does not prove a universal bypass. Microsoft’s cited defenses include LSASS Attack Surface Reduction, Protected Process Light, and Credential Guard.