EDRSilencer is a Windows-based, driverless EDR-impairment tool inspired by MdSec NightHawk’s FireBlock. It enumerates running processes associated with endpoint detection and response and security products, then uses Windows Filtering Platform APIs to create persistent IPv4 and IPv6 outbound-blocking filters for those processes. The affected agents remain running but cannot transmit telemetry, alerts, or other data to their management infrastructure, potentially making the endpoint appear disconnected or inactive. Its functions include automatically blocking detected EDR processes, blocking a specified process, and removing filters individually or in bulk. The tool has been repurposed by threat actors as a defense-evasion component, including in ransomware activity, and has been observed targeting products such as Microsoft Defender, Carbon Black, SentinelOne, and Trend Micro Vision One Endpoint Agent. EDRSilencer supports persistent filtering that can survive tool termination and system reboot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In the execution phase, the attacker runs EDRSilencer using the blockedr argument to block traffic from all detected EDR processes. Alternatively, the attacker can use the block <path> argument to block traffic from a specific process by providing its full path.
The code leverages WFP by dynamically identifying running EDR processes and creating WFP filters to block their outbound network communications on both the internet protocols IPv4 and IPv6, effectively preventing EDRs from sending telemetry or alerts to their management consoles.
When these firewall rules are created, they’re actually stored in the registry under: HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{GUID}... When filters are set, they’re stored in the registry just like firewall rules, just in a different location.
When these firewall rules are created, they’re actually stored in the registry under: HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{GUID}... When filters are set, they’re stored in the registry just like firewall rules, just in a different location.
Once kernel privileges are confirmed, the killer enumerates a hardcoded list of EDR product names, service names, driver names, and process names, and tears each one down.
Related Detections: "Windows EDRSilencer Custom Outbound Filter Added" — Technique: "Disable or Modify Tools."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A red team tool repurposed by threat actors to evade detection by identifying running EDR processes and creating persistent Windows Filtering Platform filters that block their outbound communications, preventing telemetry and alerts from reaching management consoles.
An offensive EDR-evasion tool that creates Windows Filtering Platform outbound filters, intended to suppress or disrupt endpoint security product network communications.
A Windows defense-evasion tool that creates WFP block filters to prevent outbound network communications by EDR and security-agent processes, impairing endpoint telemetry. The detection identifies its characteristic "Custom Outbound Filter" through Windows Security Event IDs 5447 and 5441.
An EDR evasion tool that suppresses telemetry by blocking the endpoint agent’s network communications instead of terminating the agent process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.