Hunting WerFaultSecure “EDR-Freeze” the right way: a technical build guide
ID: 35f2d2e8-f7cb-557a-ac5f-fe64ce77b635
STIX ID: report--35f2d2e8-f7cb-557a-ac5f-fe64ce77b635
Feed Name: Detect FYI
A detection analytic in KQL identifies suspicious use of Windows Error Reporting (WerFault/WerFaultSecure) invoked with /pid to target known EDR/XDR agent processes by correlating process events and timing, highlighting potential defensive evasion or EDR tampering activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
