logo

New malware surfaces to terminate NGAVs/EDRs/XDRs

ID: d6706586-44e9-56bf-851c-f144d3fa3289

STIX ID: report--d6706586-44e9-56bf-851c-f144d3fa3289

Feed Name: ThreatLocker Blog

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

ThreatLocker reports on an unverified claim of an executable that can disable tamper protection and terminate EDR/XDR/AV agents across numerous vendors (e.g., Microsoft Defender, CrowdStrike, SentinelOne), and emphasizes that its application allowlisting and Ringfencing can block such unauthorized executables; it advises maintaining strict allowlists within a zero-trust posture while noting the source cannot be confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.