2026-10-11 16:38 UTC

Security researcher eddie zhang claims a modified, uncensored local Qwen 3.8 27B produced an executable that dumps LSASS memory for credential harvesting while evading two modern EDR products β€” EDR-vendor acknowledgment or independent reproduction would establish local-model-generated offensive tooling as a demonstrated capability rather than a hypothetical.

state: seedheat: lowuncertainty: mediumconvergesscott: mediumlocal-model-misuse offensive-security edr-evasioneddie zhang

What is this?

Project Black researcher Eddie Zhang published a lab experiment (Sept 24) in which an AI-generated Windows LSASS credential dumper, initially caught by endpoint security tooling, was revised after a single 'make it more stealthy' request into a build that triggered no detections on either of the two EDR products in his lab. The working model was an uncensored, community-modified Qwen 3.8 27B running locally on a dual-RTX-4090 rig β€” an earlier attempt with DeepSeek tripped a safety guardrail β€” and code review shows the model independently altered process-spawning behavior, reduced access masks, inserted randomized dump delays, changed output naming, and scrubbed embedded strings. Coverage (GBHackers, Cyberpress, CybersecurityNews) is consistent on these mechanics, but all repeat the same caveats: the EDR vendors are unnamed, the test was lab-only, and there is no independent reproduction or vendor acknowledgment, so local-model-generated EDR-evasive tooling remains a single researcher's demonstrated claim rather than a verified capability.

Why it matters to Scott

A claimed single-prompt 'make it stealthy' iteration from caught-by-EDR to undetected is a concrete receipt for the attacker-search-budget premise his Breach Doesnt Compose ebook already argues, and the mechanism is Guardrail Illusion in its strongest form: refusal safety not bypassed but deleted at the weights (abliterated Qwen3.8-27B) on the same dual-RTX-4090 rig class he runs via gamepc. Verification is still open (unnamed EDRs, lab-only, no reproduction), which caps this at medium β€” vendor acknowledgment or independent replication would convert it into a dated-receipts publishing opportunity for the ebook and fresh fuel for the open-weight restriction advocacy he tracks, so worth watching rather than citing yet.
ip:source.breach-doesnt-compose-ebookip:concept.guardrail-illusiondev:concept.padded-cell-agent-architecturedev:project.gamepcip:concept.capability-symmetryradar:qwen38-abliteration-safety-tradeoffradar:heretic-model-unrestriction-toolingradar:fools-gold-safety-removal-defenseradar:concept.autonomous-cyberattacksradar:openai-anthropic-open-weight-policy-alignment
queries asked of Scott's wikis
  • uncensored or abliterated open-weight models safety removal
  • open weights misuse dual-use proliferation risk position
  • refusal training guardrails as effective safety control
  • local inference rig multi-GPU RTX 4090 setup economics
  • LLM-generated malware or offensive security tooling
  • small open model matching frontier capability claims

Measured heat

now 0 pts/hpeak 11 pts/hcomments 0/hpeers p0momentum: steady2 platformsage 434h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-23 14:00⭐ origin echo-reconstructedOriginal research writeup by pentester Eddie Zhang at Australian consultancy Project Black: "How hard is it to bypass EDR in the modern time
Project Black (Eddie Zhang) on blog (echo) Β· attributed from reddit.post.1ws7csk
β€”
09-28 06:46first on r/LocalLLaMA Β· published Β· +112.8hmodified qwen 3.8 27b modifies windows credential dumper to bypass EDR detection
MooseEfficient2151
β€”
09-28 06:46amplified on r/LocalLLaMA πŸ‘‘reddit.post.1ws7csk
MooseEfficient2151
peak 36 Β· 14 comments Β· 100% of case engagement
09-28 07:20our radar first saw it Β· +113.3hdiscovery anchor: reddit.post.1ws7cskβ€”
pace: p61 vs 1032 stories at the 336h mark (now 434h old) β€” ahead of base3-ternary-gguf-packing (1.0x), behind local-kv-cache-pressure-probe (1.0x)

Evidence (2) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditmodified qwen 3.8 27b modifies windows credential dumper to bypass EDR detection
LocalLLaMA
Retrieved article excerpt

Open article Β· Retrieved 2026-09-28T07:25:14.009613+00:00

# Prove your humanity

We’re committed to safety and security. But not for bots. Complete the challenge below and let us know you’re
a real person.

[Reddit, Inc. Β© "2026". All rights reserved.](https://www.redditinc.com/)

[User Agreement](https://www.reddit.com/help/useragreement)
[Privacy Policy](https://www.reddit.com/help/privacypolicy)
[Content Policy](https://www.reddit.com/help/contentpolicy)
[Help](https://support.reddithelp.com/hc/en-us)
MooseEfficient21513614
🟧 echo.blog ⭐Original research writeup by pentester Eddie Zhang at Australian consultancy Project Black: "How hard is it to bypass EDR in the modern timeProject Black (Eddie Zhang)β€”β€”

Interpretation history

Decision trace