New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender
ID: 30357e83-1478-52c2-8a60-d91c1c602e3e
STIX ID: report--30357e83-1478-52c2-8a60-d91c1c602e3e
Feed Name: cybersecurityNews.com
Security researcher TwoSevenOneT published EDRStartupHinder, a tool that blocks antivirus and EDR services at startup by creating a higher-priority service and using Windows Bindlink to redirect a core System32 DLL to a corrupted, unsigned copy; Protected Process Light (PPL) causes the EDR process to crash when it rejects the unsigned DLL. The technique was demonstrated in a lab against MsMpEng.exe (Windows Defender) on Windows 11 25H2, requires identifying appropriate DLLs and service groups, and is available on GitHub; suggested mitigations include monitoring bindlink usage, auditing service group priorities and signature enforcement, and hardening DLL dependencies and startup sequencing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
