---
title: "Uncovered with Clear NDR: Spyware Missed by EDR"
description: We recently made an interesting discovery while helping a customer understand the advanced hunting capabilities of Stamus NDR. The customer is a large financial institution with vast datacenter and cloud based resources and a substantially-remote workforce. Their web and mobile applications provide numerous services to the public and government. 
image: https://www.stamus-networks.com/hubfs/blog-spyware-missed-by-edr.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Uncovered with Clear NDR: Spyware Missed by EDR

 by [Peter Manev](https://www.stamus-networks.com/blog/author/peter-manev) | Feb 04, 2022 | [Network Detection and Response](https://www.stamus-networks.com/blog/tag/network-detection-and-response), [Threat Hunting](https://www.stamus-networks.com/blog/tag/threat-hunting), [Uncovered with SSP](https://www.stamus-networks.com/blog/tag/uncovered-with-ssp), [Stamus Security Platform](https://www.stamus-networks.com/blog/tag/stamus-security-platform), [ClearNDR](https://www.stamus-networks.com/blog/tag/clearndr)

![](https://www.stamus-networks.com/hubfs/blog-spyware-missed-by-edr.jpg)

In this series of articles, we explore a set of use cases that we have encountered in real-world customer deployments of our network<https://www.stamus-networks.com/network-detection-and-response?hsLang=en>detection and response solution, [Clear NDRTM](https://www.stamus-networks.com/clear-ndr?hsLang=en)<https://www.stamus-networks.com/stamus-security-platform?hsLang=en>. In each case we work to explain what we found, how we found it, and why it matters.

# Background

We recently made an interesting discovery while helping a customer understand the advanced hunting capabilities of Clear NDR. The customer is a large financial institution with vast datacenter and cloud based resources and a substantially-remote workforce. Their web and mobile applications provide numerous services to the public and government. 

In their environment, many of the clients have short IP leasing times, with most devices changing their IP address every 30 minutes. This makes it nearly impossible to lean heavily on IP addresses for threat detection. So, we were going to need to use a different approach. In addition, their network traffic consists of massive cross communication between datacenter and cloud based services.

They manage a broad security infrastructure, deploying numerous security solutions from the industry’s top security vendors.

Their network security solution from Stamus Networks is deployed with a mixture of physical and virtual probes along with the hunting and [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en) features.

# What we Found and How we Found It

While demonstrating a new detection mechanism in [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en) with the customer, we discovered that a laptop belonging to a trusted member of the infrastructure team had unintentionally installed an adware program. The agent appeared to change its objectives, and was now attempting a spyware-like exfiltration.

The new detection mechanism in [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en) - called dynamic dataset - continuously evaluates connections and traffic patterns for DNS server requests, encrypted connections, hosts, HTTP user agents, usernames, and other protocol attributes in order to identify new values, never encountered. When combined with the knowledge of an organization's critical assets, this “not seen before” event can be used to detect anomalies and otherwise unknown threats.

# How it Happened

A few days after enabling the new feature in [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en)<https://www.stamus-networks.com/stamus-security-platform?hsLang=en>, we noticed that the system was highlighting unusual communication sequences. Among the hundreds of millions of analyzed events, a specific new/unknown communication began appearing that had the following characteristics:

It highlighted numerous communications (previously unknown) coming in from the same organizational area with the following characteristics:  

- To new domains and hosts 
- At times it was repetitive 
- It was blocked on the local firewall
- It was coming from the PC belonging to a datacenter floor manager

# The Challenges

The concept of highlighting unusual data flows is not new. And it can generate an extraordinary amount of noisy events and is problematic if not handled properly. For example, the newly discovered activity can be triggered by a number of behaviors such as a DNS request to an encrypted connection or a DNS request over HTTPS (DoH) DNS over TLS. There are constantly changing and dynamic public cloud services available too. Here, there are many EDR/AV solutions that use DNS tunneling for regular updates/sync etc making detections like this appear to be false positives.

What is important here is to not rely on one factor alone. In this case Clear NDR allowed us to pinpoint everything very quickly based on a set of features combining multiple metadata factors, such as: flow data and size, protocol logs, organizational information, communication age.

<https://www.stamus-networks.com/stamus-security-platform?hsLang=en>Clear NDR provides the user with the tools to take this combination of factors into consideration, including auto classification and alert triage. So we were able to quickly filter out through those hundreds of millions of events and zoom right in on the trusted user belonging to a trusted infrastructure team.

At first glance it looked like the communications were blocked by the firewall, making it appear as though it was successfully blocked and harmless. However, Clear NDR<https://www.stamus-networks.com/stamus-ndr?hsLang=en>highlighted the communication coming from a laptop currently inside the organization trying to get out. Imagine if this laptop moves outside the network - to a public WiFi in a coffee shop somewhere downtown, for example. This spyware would likely make similar exfiltration attempts. And this time it would be successful. 

As we look more closely, we will want to answer some really important questions:

- What is it? 
- Who is it? 
- What does the data look like? 
- What is it trying to do ?

The answers were easy to come - in just a few clicks - by using the enriched hunting capabilities of [Clear NDR](https://www.stamus-networks.com/stamus-ndr?hsLang=en).

Here are some forensic logs and detection evidence we can share.

Highlighted “Not Seen Before” communications

![Uncovered Spyware - Figure 1](https://www.stamus-networks.com/hs-fs/hubfs/Uncovered%20Spyware%20-%20Figure%201.jpeg?width=2999&name=Uncovered%20Spyware%20-%20Figure%201.jpeg)

The enriched communications data

![Uncovered Spyware - Figure 2](https://www.stamus-networks.com/hs-fs/hubfs/Uncovered%20Spyware%20-%20Figure%202.jpeg?width=3999&name=Uncovered%20Spyware%20-%20Figure%202.jpeg)

A more detailed view

![Uncovered Spyware - Figure 3](https://www.stamus-networks.com/hs-fs/hubfs/Uncovered%20Spyware%20-%20Figure%203.jpeg?width=3522&name=Uncovered%20Spyware%20-%20Figure%203.jpeg)

Here you can see that the attempted transfers used periodic time windows when it tried to exfiltrate the system and personal data.

![Uncovered Spyware - Figure 5](https://www.stamus-networks.com/hs-fs/hubfs/Uncovered%20Spyware%20-%20Figure%205.jpeg?width=3999&name=Uncovered%20Spyware%20-%20Figure%205.jpeg)

The user and relevant organizational role were quickly identified (User A, job position: datacenter floor manager.)

![Uncovered Spyware - Figure 4](https://www.stamus-networks.com/hs-fs/hubfs/Uncovered%20Spyware%20-%20Figure%204.jpeg?width=3999&name=Uncovered%20Spyware%20-%20Figure%204.jpeg)

The “Host Insights” function of Clear NDR (shown above) automatically identifies and fingerprints all user and computer accounts associated with a specific host. That allowed us to quickly determine that the account of the user currently exhibiting this behavior was actually a floor manager on duty in one of the corporate data centers.

The customer helped us investigate the relevant endpoint logs, and we identified those exfiltration requests as coming from an unauthorized adware extension installed in the user’s standard browser included with PC kits. 

# Why this Matters

In the end, we confirmed that this spyware had managed to evade the endpoint defenses (EDR) and the company-wide browser restrictions.

Detecting this from the network allowed the customer to open an incident and engage their EDR/SoC teams to evaluate further impact and other potential points of quarantine that may be needed.

This is an example of an unintended/unwanted software install that escalated to an attempted exfiltration of company and personal data. And the attack was perpetrated through a user with trusted administrative privileges to the organization's critical IT infrastructure. 

We are confident that if this incident was not detected, it would have escalated to become much worse and result in monetary or infrastructure damages to the company. 

# More Information

Hopefully this gives you a taste of how Clear NDR can help security teams know more, respond sooner, and mitigate the risk to their organizations.

To read more articles in this series, check out these "Uncovered with Stamus NDR" blogs:

- [Uncovered with Clear NDR: ModiRAT ](https://www.stamus-networks.com/blog/uncovered-with-ssp-modi-rat?hsLang=en)
- [Uncovered with Clear NDR: Shadow IT ](https://www.stamus-networks.com/blog/uncovered-with-ssp-shadow-it?hsLang=en)
- [Uncovered with Clear NDR: Danger in the Data Center](https://www.stamus-networks.com/blog/uncovered-with-stamus-ndr-danger-in-the-datacenter?hsLang=en) 
- [Uncovered with Clear NDR: User Agents Tell the Story ](https://www.stamus-networks.com/blog/network-intrusion-detected-with-suspicious-user-agents?hsLang=en)

And if you’d like to see [Clear NDR](https://www.stamus-networks.com/clear-ndr?hsLang=en) in action, please click on the link below to schedule a live demonstration. 

[![Request a Demo](https://no-cache.hubspot.com/cta/default/6344338/e742849f-5a06-447c-9027-f4590e1e7a82.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/e742849f-5a06-447c-9027-f4590e1e7a82)

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funcovered-with-stamus-ndr-spyware-missed-by-edr%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Peter Manev](https://www.stamus-networks.com/hubfs/Stamus_Peter_Square-1.jpg)

#### Peter Manev

 Peter Manev is the co-founder and chief strategy officer (CSO) at Stamus Networks. He is a member of the executive team at Open Network Security Foundation (OISF). Peter has over 20 years of experience in the IT industry, including enterprise-level IT security practice. He is a passionate user, developer, and explorer of innovative open-source security software, and he is responsible for training as well as quality assurance and testing on the development team of Suricata – the open-source threat detection engine. Peter is a regular speaker and educator on open-source security, threat hunting, and network security at conferences and live-fire cyber exercises, such as Crossed Swords, DeepSec, Troopers, DefCon, RSA, Suricon, SharkFest, and others. Peter resides in Gothenburg, Sweden.

[**](https://www.linkedin.com/in/peter-manev-64918336/) [** ](https://twitter.com/pevma)

## Schedule a Demo of Stamus Security Platform

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/hubfs/SN-EDR-Goes-Dark-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

### [When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

I've spent a significant part of my career participating in [NATO cyber defense exercises](https://www.stamus-networks.com/nato-ccdcoe-participation?hsLang=en) -...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.