EDRSilencer
EDRSilencer is a driverless Windows EDR killer and security-solution tampering tool designed to impair endpoint detection and response products by blocking their network communications rather than terminating them with a kernel driver. According to the provided content, it was inspired by MdSec NightHawk’s closed-source FireBlock tool and uses Windows Filtering Platform (WFP) APIs to identify running EDR processes and apply filters that block their outbound traffic, causing affected products to lose communication with their backends and potentially enter a "coma-like" state. Reported functionality includes searching for running EDR processes, adding WFP filters for specific processes, removing filters individually or globally, and a custom CreateFileW bypass to avoid file-handle access issues with EDR processes. The content states that it supports Microsoft Defender, Carbon Black, SentinelOne, and additional EDR products, and that it has been tested on Windows 10 and Windows Server 2016. ESET describes EDRSilencer as part of an emerging class of driverless EDR killers that ransomware actors are adopting quickly as a pre-encryption defense-evasion stage. Splunk published a detection for its execution on Windows, looking for EDRSilencer.exe or command lines containing "blockedr" while excluding "blockedreport," using telemetry such as CrowdStrike ProcessRollup2, Sysmon Event ID 1, and Windows Security Event ID 4688. A referenced public repository is github.com/netero1010/EDRSilencer.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Other
3 techniques
Other
In this article I present a technique for interfering with the client–server connection of an EDR... Once an EDR agent loses contact with its server, much of its power is gone.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows tool used to impair or silence EDR products by locating running EDR processes and applying Windows Filtering Platform filters to block their outbound traffic. It can add or remove filters and includes a custom method to bypass CreateFileW-related handle access issues.
A driverless EDR killer that blocks outbound traffic from EDR products, causing them to become ineffective or enter a coma-like state.
Driverless EDR killer that blocks communication between the endpoint and the security backend to impair defenses.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.