logo

Filter-Mute Operation: Investigating EDR Internal Communication

ID: f9c13a98-f33f-523f-8792-47b1c89894c5

STIX ID: report--f9c13a98-f33f-523f-8792-47b1c89894c5

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2023-07-28

Date Updated: 2026-04-30

...
...

This report documents the “filter-mute” technique that disables communication between EDR kernel drivers and their user-mode agents by zeroing the FLT_SERVER_PORT_OBJECT MaxConnections value via a kernel R/W primitive (BYOVD). It includes Windbg-guided kernel-walking to locate the field, a PoC tool (EDRSnowblast) to automate the change, demonstration steps (kill the user-mode service, copy malicious payload), observed success against Windows Defender and two other vendors, prerequisites for the attack (kernel R/W or loadable vulnerable driver and ability to kill the EDR process), and recommended mitigations such as VBS/HVCI, driver block rules, and driver hardening techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.