logo

Security End-Run: 'AuKill' Shuts Down Windows-Reliant EDR Processes

ID: b86c23ee-b357-5283-907f-2dc5fdcedf16

STIX ID: report--b86c23ee-b357-5283-907f-2dc5fdcedf16

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-07-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

AuKill, developed by FIN7, is an anti-endpoint security tool that employs over ten user- and kernel-mode techniques to tamper with and terminate protected Windows EDR processes. A newly documented technique uses the Windows time-travel debugging (TTD) monitor driver together with an updated Process Explorer driver to suspend protected parent processes and block child helper processes, inducing crashes/denial-of-service; SentinelOne observed AuKill being used by multiple ransomware families (Black Basta, AvosLocker, BlackCat, LockBit). The report advises enabling robust anti-tampering protections, kernel-level monitoring, and restricting driver access to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.