New malware surfaces to terminate NGAVs/EDRs/XDRs
ID: d6706586-44e9-56bf-851c-f144d3fa3289
STIX ID: report--d6706586-44e9-56bf-851c-f144d3fa3289
Feed Name: ThreatLocker Blog
ThreatLocker reports on an unverified claim of an executable that can disable tamper protection and terminate EDR/XDR/AV agents across numerous vendors (e.g., Microsoft Defender, CrowdStrike, SentinelOne), and emphasizes that its application allowlisting and Ringfencing can block such unauthorized executables; it advises maintaining strict allowlists within a zero-trust posture while noting the source cannot be confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
