Silencing the EDR Silencers | Huntress
ID: 0e48ea48-a481-5539-9a20-bb960a233c3f
STIX ID: report--0e48ea48-a481-5539-9a20-bb960a233c3f
Feed Name: Huntress Blog
This blog describes how attackers can 'blind' EDRs by creating Windows Defender Firewall rules and Windows Filtering Platform (WFP) filters to block EDR network communications, details where those rules/filters are stored in the registry, references tooling used in the wild, and proposes two mitigation approaches: prevent registry writes via kernel RegNtPreSetValueKey callbacks or immediately remove malicious rules/filters via post-callback handling and user-mode removal using INetFwRules and WFP APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
