Palo Alto Networks Cortex XDR was awarded SE Labs Anti-Tamper Certification, following successful testing designed to assess whether endpoint security can continue protecting a system when the security product itself comes under attack.
Most endpoint security tests ask whether a product can protect an endpoint from threats. SE Labs’ anti-tamper certification turns that question around: can the product continue protecting the endpoint when an attacker deliberately tries to disable, disrupt or blind it?
During testing, Cortex XDR faced attempts to switch it off, interfere with its monitoring, prevent it from starting, cut its communications and remove critical components. The assessment also examined whether attempts to tamper with the product allowed the attacker to continue with harmful activity.
Cortex XDR remained resilient against SE Labs’ attempts to disable or disrupt its protection and successfully achieved Anti-Tamper Certification.
“We congratulate Palo Alto Networks on Cortex XDR achieving SE Labs Anti-Tamper Certification,” says Simon Edwards, CEO and founder of SE Labs. “The result provides independent evidence that, in our testing, the product remained resilient against determined attempts to disable, disrupt or blind its protection, continuing to defend the system when it mattered most.”
Tampering with cyber security products can take many forms, from modifying registry settings and interfering with security processes to manipulating drivers, injecting code or altering product configurations. An attacker may also attempt to block the indicators and communications that a security product relies on to detect or report malicious activity.
If successful, these techniques can create an opportunity to steal credentials, establish persistence, move across the network, exfiltrate data or deploy ransomware with less chance of being stopped.
SE Labs’ Anti-Tamper Certification assesses whether endpoint security products can continue protecting a system even when they are deliberately targeted in this way. Rather than testing a product only under normal operating conditions, the certification places the product’s protective capabilities directly within the attacker’s path.
For more information on SE Labs anti-tamper testing and certification, please visit our blog: https://selabs.uk/blog/can-endpoint-security-protect-itself-from-attackers/↗