Security End-Run: 'AuKill' Shuts Down Windows-Reliant EDR Processes
ID: b86c23ee-b357-5283-907f-2dc5fdcedf16
STIX ID: report--b86c23ee-b357-5283-907f-2dc5fdcedf16
Feed Name: Dark Reading
AuKill, developed by FIN7, is an anti-endpoint security tool that employs over ten user- and kernel-mode techniques to tamper with and terminate protected Windows EDR processes. A newly documented technique uses the Windows time-travel debugging (TTD) monitor driver together with an updated Process Explorer driver to suspend protected parent processes and block child helper processes, inducing crashes/denial-of-service; SentinelOne observed AuKill being used by multiple ransomware families (Black Basta, AvosLocker, BlackCat, LockBit). The report advises enabling robust anti-tampering protections, kernel-level monitoring, and restricting driver access to mitigate these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
