logo

EnCase Driver Weaponized as EDR Killers Persist

ID: 593d7c4f-1a39-577e-8b0b-661af9c1dc9f

STIX ID: report--593d7c4f-1a39-577e-8b0b-661af9c1dc9f

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Threat actors gained access via compromised SonicWall VPN credentials and deployed a disguised 64-bit binary that embedded a revoked EnCase kernel driver to terminate EDR/antivirus processes (a BYOVD/EDR-killer technique). Huntress detected and disrupted the intrusion, analyzed the wordlist-obfuscated payload and recommended mitigations including enforcing MFA for VPNs, applying Microsoft-recommended driver block rules (WDAC), and enabling HVCI to enforce the Vulnerable Driver Blocklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.