EDR-Redir is an EDR evasion technique/tool associated with security researcher TwoSevenOneT. The provided content identifies it as a prior-generation approach that redirected EDR folders after startup, in contrast to the newer EDRStartupHinder method that targets startup-loaded System32 DLLs before the protected EDR process initializes. The content explicitly states that vendors hardened against post-startup redirection techniques like EDR-Redir, and references a variant titled "EDR-Redir-V2 - Blind EDR With Fake Program Files." Based on the available content, EDR-Redir is intended to interfere with endpoint security products by redirecting their files or folders after startup, but no additional high-confidence details are provided regarding infection vector, specific targeted industries, associated threat actors, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
EDR evasion technique/tool that redirects EDR folders after startup to interfere with EDR operation; described as a prior approach that vendors have since hardened against.
Technique/tooling to mislead/blind EDR by manipulating perceived parent/working directories (e.g., Defender seeing a fixed temp directory as parent).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.