logo

Silencing the EDR Silencers | Huntress

ID: 0e48ea48-a481-5539-9a20-bb960a233c3f

STIX ID: report--0e48ea48-a481-5539-9a20-bb960a233c3f

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-10-29

Date Updated: 2026-04-28

...
...

This blog describes how attackers can 'blind' EDRs by creating Windows Defender Firewall rules and Windows Filtering Platform (WFP) filters to block EDR network communications, details where those rules/filters are stored in the registry, references tooling used in the wild, and proposes two mitigation approaches: prevent registry writes via kernel RegNtPreSetValueKey callbacks or immediately remove malicious rules/filters via post-callback handling and user-mode removal using INetFwRules and WFP APIs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.