logo

Hunting WerFaultSecure “EDR-Freeze” the right way: a technical build guide

ID: 35f2d2e8-f7cb-557a-ac5f-fe64ce77b635

STIX ID: report--35f2d2e8-f7cb-557a-ac5f-fe64ce77b635

Feed Name: Detect FYI

Date Published: 2026-01-08

Date Updated: 2026-04-19

Author: Omar Tarek Zayed

...
...

A detection analytic in KQL identifies suspicious use of Windows Error Reporting (WerFault/WerFaultSecure) invoked with /pid to target known EDR/XDR agent processes by correlating process events and timing, highlighting potential defensive evasion or EDR tampering activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.