logo

Defense Evasion Techniques Detected by AhnLab EDR

ID: 9e929254-2741-5a6f-92e7-b4327eedc2f4

STIX ID: report--9e929254-2741-5a6f-92e7-b4327eedc2f4

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-03-18

Date Updated: 2026-04-26

Author: Sanseo

...
...

**AhnLab analysis of defense-evasion tools:** This report documents how threat actors leverage legitimate tools (Defender Control, HRSword, Process Hacker, GMER) to disable endpoint security during intrusions, cites observed usage by ransomware groups and APTs (e.g., LockBit, Ryuk, Mimic, Lapsus$), and details how AhnLab EDR detects these behaviors to enable early warning, investigation, and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.