This blog post will start by explaining the blind spots created by event-driven detection solutions such as Endpoint Detection & Response (EDR), and how this can be balanced by using Comae DumpIt + Stardust as part of an incident response & compromise assessment strategy. — CIA Vault 7: From Kernel to User Mode: APC Injection.> April 2013 — According to documents leaked by TheShadowBrokers, DOUBLEPULSAR (which leverages User APC code injection) targeted a SWIFT Service Bureau in the Middle East.> April 2017 — TheShadowBrokers releases offensive tools including Windows exploits/tools: DOUBLEPULSAR, ETERNALBLUE etc.> 21, April 2017 — Analysis of DOUBLEPULSAR by zerosum0x0> May 2017 — Comae Stardust adds detection for DOUBLEPULSAR.> May 2017 — WannaCry happens and uses ETERNALBLUE +…