logo

EDRStartupHinder: Blocks Antivirus & EDR at Windows 11 25H2 Startup (Defender Included)

ID: b5ada496-bd08-5d8e-a27c-da4067b31f13

STIX ID: report--b5ada496-bd08-5d8e-a27c-da4067b31f13

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

EDRStartupHinder is a proof-of-concept tool that prevents EDR/antivirus products (including Windows Defender) from launching at Windows startup by using the Bindlink API (bindflt.sys) to redirect System32 DLL loads to corrupted, unsigned copies; when PPL-protected EDR processes attempt to load the invalid DLL they terminate, after which the redirect is removed. The technique was tested successfully against Defender and several commercial EDRs, requires administrator privileges, and highlights the need to monitor for suspicious service creation and DLL redirection as indicators of this attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.