Security researcher eddie zhang claims a modified, uncensored local Qwen 3.8 27B produced an executable that dumps LSASS memory for credential harvesting while evading two modern EDR products β EDR-vendor acknowledgment or independent reproduction would establish local-model-generated offensive tooling as a demonstrated capability rather than a hypothetical.
state: seedheat: lowuncertainty: mediumconvergesscott: mediumlocal-model-misuse offensive-security edr-evasioneddie zhang
What is this?
Project Black researcher Eddie Zhang published a lab experiment (Sept 24) in which an AI-generated Windows LSASS credential dumper, initially caught by endpoint security tooling, was revised after a single 'make it more stealthy' request into a build that triggered no detections on either of the two EDR products in his lab. The working model was an uncensored, community-modified Qwen 3.8 27B running locally on a dual-RTX-4090 rig β an earlier attempt with DeepSeek tripped a safety guardrail β and code review shows the model independently altered process-spawning behavior, reduced access masks, inserted randomized dump delays, changed output naming, and scrubbed embedded strings. Coverage (GBHackers, Cyberpress, CybersecurityNews) is consistent on these mechanics, but all repeat the same caveats: the EDR vendors are unnamed, the test was lab-only, and there is no independent reproduction or vendor acknowledgment, so local-model-generated EDR-evasive tooling remains a single researcher's demonstrated claim rather than a verified capability.
Why it matters to Scott
A claimed single-prompt 'make it stealthy' iteration from caught-by-EDR to undetected is a concrete receipt for the attacker-search-budget premise his Breach Doesnt Compose ebook already argues, and the mechanism is Guardrail Illusion in its strongest form: refusal safety not bypassed but deleted at the weights (abliterated Qwen3.8-27B) on the same dual-RTX-4090 rig class he runs via gamepc. Verification is still open (unnamed EDRs, lab-only, no reproduction), which caps this at medium β vendor acknowledgment or independent replication would convert it into a dated-receipts publishing opportunity for the ebook and fresh fuel for the open-weight restriction advocacy he tracks, so worth watching rather than citing yet.
ip:source.breach-doesnt-compose-ebookip:concept.guardrail-illusiondev:concept.padded-cell-agent-architecturedev:project.gamepcip:concept.capability-symmetryradar:qwen38-abliteration-safety-tradeoffradar:heretic-model-unrestriction-toolingradar:fools-gold-safety-removal-defenseradar:concept.autonomous-cyberattacksradar:openai-anthropic-open-weight-policy-alignment
queries asked of Scott's wikis
- uncensored or abliterated open-weight models safety removal
- open weights misuse dual-use proliferation risk position
- refusal training guardrails as effective safety control
- local inference rig multi-GPU RTX 4090 setup economics
- LLM-generated malware or offensive security tooling
- small open model matching frontier capability claims
Measured heat
now 0 pts/hpeak 11 pts/hcomments 0/hpeers p0momentum: steady2 platformsage 434h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion
How the heat travelled
pace: p61 vs 1032 stories at the 336h mark (now 434h old) β ahead of base3-ternary-gguf-packing (1.0x), behind local-kv-cache-pressure-probe (1.0x)
Evidence (2) β β canonical anchor
Interpretation history
2026-09-28T07:54:03Z
origin walked (opencode/cheap-glm, conf 0.93): anchor reddit.post.1ws7csk -> echo.blog.b0eb9712a3 by Project Black (Eddie Zhang)
2026-09-28T07:43:51Z
grounded: converges/medium β A claimed single-prompt 'make it stealthy' iteration from caught-by-EDR to undetected is a concrete receipt for the attacker-search-budget premise his Breach Do
2026-09-28T07:35:27Z
case created β A named researcher's concrete demonstration of uncensored local models producing EDR-evasive credential tooling is a bounded security episode with resolvable follow-ups, echoed on LocalLLaMA with no existing case.
Decision trace
- 09-29 19:58review_screenLocalLLaMA comments add only general anecdotes about Qwen agents (router config jailbreak, coding/RE automation, workflow bot) and one vague ad accusation; none independently reproduce the LSASS-dumpi
- 09-29 19:57review_screenjev screen borderline (noul=0.39) β luna review
- 09-29 12:22sensor_dirtycomment_update
- 09-28 23:21sensor_dirtycomment_update
- 09-28 17:54promote_anchororigin walk conf 0.93
- 09-28 17:43groundA claimed single-prompt 'make it stealthy' iteration from caught-by-EDR to undetected is a concrete receipt for the attacker-search-budget premise his Breach Doesnt Compose ebook already arg
- 09-28 17:35createA named researcher's concrete demonstration of uncensored local models producing EDR-evasive credential tooling is a bounded security episode with resolvable follow-ups, echoed on LocalLLaMA with