All posts

Can Endpoint Security Protect Itself from Attackers?

Getting into an organisation is only the first objective for many attackers. Once they have established access, they may try to weaken or disable the security product intended to stop them. This leaves the attacker free to continue with far less risk of detection or interruption.

Tampering can take many forms, from modifying registry settings and interfering with security processes to manipulating drivers, injecting code or altering product configurations. An attacker may also attempt to block the indicators and communications that a security product relies on to detect or report malicious activity.

If successful, these techniques can create an opportunity to steal credentials, establish persistence, move across the network, exfiltrate data or deploy ransomware with less chance of being stopped.

SE Labs’ Anti-Tamper Certification assesses whether endpoint security products can continue protecting a system even when they are deliberately targeted in this way. Rather than testing a product only under normal operating conditions, the certification places the product’s protective capabilities directly within the attacker’s path.

Testing Protection Under Attack

The certification test uses structured attack scenarios drawn from SE Labs’ threat intelligence, which includes a database of adversary techniques and tools used to emulate real-world threat actors.

Before being used against a security product, each test case is applied to a vulnerable target system. This confirms that the technique works as intended and is capable of producing the expected result on an unprotected system in a variety of different target environments, including Windows endpoints, Windows servers and Linux-based devices.

Only after this verification is the scenario applied to a system protected by the product under test. This ensures that a product cannot receive credit for preventing an attack that wouldn’t have worked in the first place.

Scenarios are selected from SE Labs Threat Series, which are updated as new techniques and tools are discovered. This allows the certification to develop alongside the threat landscape rather than remaining tied to a fixed collection of historical attacks.

Starting From Different Stages of a Compromise

Not every scenario begins with a malicious file arriving on a clean endpoint. The anti-tamper test supports several initial attack vectors, including malicious email attachments, direct-download web threats, exploit-based web attacks and access gained using compromised credentials.

Some scenarios begin with an attacker already established on the endpoint. This represents a system that was compromised before the security product was deployed, with the attacker’s foothold and persistence confirmed before testing begins.

Although most organisations strive to keep their systems and networks secure, it’s not always possible to deploy or replace security products in pristine environments. A newly installed product may need to identify and contain malicious activity that is already present, while resisting attempts by the established attacker to interfere with its operation.

Depending on the scenario, the attempt to tamper with a cyber security product may therefore follow initial access, an existing foothold or movement from another compromised system.

Following the Attack Beyond the Tampering Attempt

The test does not end as soon as a product detects suspicious activity. Detection of an attack technique does not necessarily mean that the system has been protected from it.

Instead, SE Labs follows the scenario through a series of defined attack stages. These can include initial access or an existing foothold, the tamper attempt itself, unauthorised actions on the original endpoint, lateral movement and subsequent activity on a secondary machine.

Following the attack in this way establishes whether an attempted modification had a meaningful effect. If the attacker appears to interfere with a security process but cannot subsequently perform harmful actions, the result is different from a scenario in which protection is weakened and the attacker is able to continue.

Unauthorised activity may include discovering local processes or network connections, accessing credentials, recording keystrokes, creating persistence, downloading files or exfiltrating information. Other scenarios may assess whether the attacker can move tools to another endpoint and carry out further actions there.

Our scoring reflects the distinction between observing an attack and stopping its consequences. Penalties are applied when the attacker is able to execute harmful actions at a particular stage. A successful tampering attempt receives the largest penalty because it represents a direct failure of the product’s ability to defend itself.

Protection Without Unnecessary Disruption

A security product must also be capable of resisting tampering without obstructing legitimate work.

In order to achieve this, we also include non-malicious applications, websites and scripts to check for false positive detections and other forms of unnecessary interference. This includes newly released software and internally developed scripts of the type that a system administrator might use within an organisation.

The legitimate applications are divided between software already present when the security product is deployed and applications introduced afterwards. The security product is expected to allow existing software to operate normally and new applications to be installed with little or no unnecessary friction.

Our testers record whether legitimate activity is misclassified, blocked or subjected to warnings and user prompts. This helps distinguish effective anti-tamper protection from controls that simply restrict large amounts of system activity regardless of whether it is harmful.

Independent Validation of Tamper Resilience

Security controls need to remain operational even when an attacker is actively trying to neutralise them.

SE Labs Anti-Tamper Certification provides independent evidence that a product has been assessed against sustained attempts to undermine its protection, not simply evaluated while operating under normal conditions. It examines whether the product can resist interference, prevent the attack from progressing and provide useful information about what took place.

For cyber security vendors, the certification offers a clear way to demonstrate the resilience of their technology using transparent, repeatable attack scenarios. For buyers and security teams, it provides greater confidence that the protection they deploy has been tested against an attacker who is deliberately trying to remove it from the equation.

Palo Alto Networks Cortex XDR recently underwent SE Labs’ Anti-Tamper Certification, facing attempts to switch it off, blind its monitoring, prevent it from starting, cut its communications and remove critical components. It remained resilient against our determined attempts to disable or disrupt its protection, continuing to defend the system when it mattered most – and successfully achieving certification.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us