logo

New GhostLocker Tool that Uses Windows AppLocker to Neutralize and Control EDR

ID: b493b0ff-44c3-570b-b0b5-25cffd456c88

STIX ID: report--b493b0ff-44c3-570b-b0b5-25cffd456c88

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Guru Baran

...
...

GhostLocker is a publicly released research tool that automates deploying AppLocker deny policies to prevent EDR userland components from launching or restarting, rendering modern EDR solutions ineffective after a reboot by blinding their user-mode analysis engines while kernel drivers remain loaded. The report demonstrates complete neutralization in tests, contrasts this approach with kernel-level WDAC protections, and recommends monitoring AppLocker policy changes and using APIs to pre-validate security product execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.