logo

Disabling AV With Process Suspension

ID: b44a3ca8-7f17-5e80-af38-d2baf3cfe20e

STIX ID: report--b44a3ca8-7f17-5e80-af38-d2baf3cfe20e

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This research post demonstrates a technique to suspend Windows Defender and other protected processes using beacon object files to perform LSASS minidumps (enabling Mimikatz use), highlighting an oversight where suspend/resume access is permitted while terminate is blocked; the author warns of system instability and logging blind spots, encourages vendors to close the gap, and suggests Sysmon-based detections as partial mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.