In a recent experiment, a locally hosted artificial intelligence model successfully modified a Windows credential-dumping tool to evade detection by two Endpoint Detection and Response (EDR) systems. Conducted by Project Black researcher Eddie Zhang, the study focused on the Local Security Authority Subsystem Service (LSASS), which stores authentication data that can be exploited for lateral movement once administrative access is achieved. The experiment aimed to determine whether AI could autonomously create an executable to dump LSASS without alerting modern EDR systems, a task tracked as part of the MITRE ATT&CK framework under Credential Access.
Initial attempts using Claude Opus 5, Opus 4.8, and Sonnet 5 models were unsuccessful due to immediate refusals, despite organizational approval under Anthropic’s Cyber Verification Program. A breakthrough came with the DeepSeek v4 Flash 0731 model, which, after several prompts, generated an executable capable of creating a minidump of the LSASS process. This dump, once validated, was still detectable by EDR systems. Seeking further stealth, Zhang turned to an uncensored, community-modified Qwen 3.8 27B model, which ran locally on high-performance hardware.
With minimal guidance, the Qwen model produced a modified executable that avoided EDR detection. Code analysis revealed changes such as altered process-spawning behavior, reduced access mask requests, randomized delays during minidump creation, and scrubbing of embedded strings, all contributing to its stealth. While the experiment did not name the EDR vendors or provide configuration details, it underscores the potential for AI to adapt known offensive tools without the need for expert intervention or cloud resources.
The findings emphasize the importance of treating EDR as one component of a layered defense strategy. Microsoft advises enabling specific security rules like the LSASS credential-stealing Attack Surface Reduction rule and deploying features such as Credential Guard. Organizations should also focus on minimizing local administrator rights, segregating privileged accounts, and monitoring for unusual access to LSASS, as well as quickly isolating systems exhibiting credential-dumping behavior.

