logo

EDR killers explained: Beyond the drivers

ID: 98d6b274-00da-59db-8074-1f9f5be6a235

STIX ID: report--98d6b274-00da-59db-8074-1f9f5be6a235

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-05-01

...
...

ESET Research examines the widespread use of almost 90 "EDR killers" in modern ransomware operations, describing how affiliates adopt BYOVD vulnerable drivers, anti-rootkits, scripts, and emerging driverless tools to disable EDR/AV prior to encryption; the report includes threat actor examples, commercialization trends, IoCs (file hashes and vulnerable drivers), MITRE ATT&CK mappings, and recommends multilayered defenses beyond simple driver blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.