New EDR-Freeze tool uses Windows WER to suspend security software (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 23 Sep 16:45
https://sh.itjust.works/post/46612612

#cybersecurity

threaded - newest

BCOVertigo@lemmy.world on 23 Sep 20:18 collapse

The author’s writeup: zerosalarium.com/…/countering-edrs-with-backing-o…

Detection logic: To prevent or monitor whether EDR-Freeze is being used on the network, we should rely on the running parameters of WerFaultSecure. If it points to the PID of sensitive processes such as LSASS, Antivirus, or EDR agents, there is a high likelihood that further investigation is necessary.