EnCase Driver Weaponized as EDR Killers Persist
ID: 593d7c4f-1a39-577e-8b0b-661af9c1dc9f
STIX ID: report--593d7c4f-1a39-577e-8b0b-661af9c1dc9f
Feed Name: Dark Reading
Threat actors gained access via compromised SonicWall VPN credentials and deployed a disguised 64-bit binary that embedded a revoked EnCase kernel driver to terminate EDR/antivirus processes (a BYOVD/EDR-killer technique). Huntress detected and disrupted the intrusion, analyzed the wordlist-obfuscated payload and recommended mitigations including enforcing MFA for VPNs, applying Microsoft-recommended driver block rules (WDAC), and enabling HVCI to enforce the Vulnerable Driver Blocklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
