logo

Using Memory Analysis to Detect EDR-Nullifying Malware

ID: c203b600-607d-55c4-9775-5d026085fded

STIX ID: report--c203b600-607d-55c4-9775-5d026085fded

Feed Name: Volexity Blog

Threat Score
78/100

Date Published: 2023-03-07

Date Updated: 2026-05-01

...
...

This Volexity analysis describes AVBurner, a kernel-space evasion tool tied to an APT (SnakeCharmer/Earth Longzhi) that disables EDR/AV process-creation callbacks by using a vulnerable driver (RTCore64.sys) to patch the PspCreateProcessNotifyRoutine callback array; the report explains the internals of the Windows callback mechanism, demonstrates detection via Volatility 3 and Volexity Volcano, lists IOCs (including targeted SYS metadata and the vulnerable driver), and recommends monitoring for BYOVD drivers and applying Microsoft driver-block mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.