Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State

New EDR-Freeze Tool That Puts EDRs And Antivirus Into A Coma State

Posted on September 21, 2025September 21, 2025 By CWS

A brand new proof-of-concept software named EDR-Freeze has been developed, able to putting Endpoint Detection and Response (EDR) and antivirus options right into a suspended “coma” state.

In accordance with Zero Salarium, the method leverages a built-in Home windows operate, providing a stealthier different to the more and more widespread Deliver Your Personal Weak Driver (BYOVD) assaults utilized by menace actors to disable safety software program.

Not like BYOVD strategies, which require introducing a weak driver onto a goal system, EDR-Freeze exploits reputable elements of the Home windows working system.

This strategy avoids the necessity to set up third-party drivers, lowering the danger of system instability and detection. Your entire course of is executed from user-mode code, making it a delicate and efficient strategy to quickly neutralize safety monitoring.

The MiniDumpWriteDump Exploit

The core of the EDR-Freeze method lies within the manipulation of the MiniDumpWriteDump operate. This operate, a part of the Home windows DbgHelp library, is designed to create a minidump, a snapshot of a course of’s reminiscence for debugging functions.

To make sure a constant and uncorrupted snapshot, the operate suspends all threads inside the goal course of whereas the dump is created.

Ordinarily, this suspension is temporary. Nevertheless, the developer of EDR-Freeze devised a way to delay this suspended state indefinitely.

EDR-Freeze Instrument

The first challenges had been twofold: extending the very quick execution time of the MiniDumpWriteDump operate and bypassing the Protected Course of Mild (PPL) safety function that shields EDR and antivirus processes from tampering.

To beat PPL safety, the method makes use of WerFaultSecure.exe, a element of the Home windows Error Reporting (WER) service. WerFaultSecure.exe can run with WinTCB degree safety, one of many highest privilege ranges, permitting it to work together with protected processes.

By crafting the proper parameters, WerFaultSecure.exe will be instructed to provoke the MiniDumpWriteDump operate on any goal course of, together with protected EDR and antivirus brokers.

The ultimate piece of the puzzle is a race-condition assault that turns a momentary suspension into a chronic freeze. The assault unfolds in a fast, exact sequence:

WerFaultSecure.exe is launched with parameters directing it to create a reminiscence dump of the goal EDR or antivirus course of.

The EDR-Freeze software constantly screens the goal course of.

The second the goal course of enters a suspended state (as MiniDumpWriteDump begins its work), the EDR-Freeze software instantly suspends the WerFaultSecure.exe course of itself.

As a result of WerFaultSecure.exe is now suspended, it may by no means full the reminiscence dump operation and, crucially, can by no means resume the threads of the goal EDR course of.

The result’s that the safety software program is left in a everlasting state of suspension, successfully blinded, till the WerFaultSecure.exe course of is terminated, Zero Salarium mentioned.

The developer has launched the EDR-Freeze software to exhibit this system. It takes two easy parameters: the Course of ID (PID) of the goal to be frozen and the period of the suspension in milliseconds.

This enables an attacker to disable safety instruments, carry out malicious actions, after which enable the safety software program to renew regular operations as if nothing had occurred.

A check on Home windows 11 24H2 efficiently suspended the MsMpEng.exe strategy of Home windows Defender.

EDR-Freeze Instrument Kills EDR and Antivirus

For defenders, detecting this system includes monitoring for uncommon executions of WerFaultSecure.exe.

If this system is noticed focusing on the PIDs of delicate processes like lsass.exe or EDR brokers, it ought to be handled as a high-priority safety alert requiring fast investigation.

Discover this Story Attention-grabbing! Observe us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:Antivirus, Coma, EDRFreeze, EDRs, Puts, State, Tool

Post navigation

Previous Post: Cyberattack Disrupts Check-In Systems at Major European Airports
Next Post: DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams

Related Posts

Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Cyber Security News
Microsoft Office Vulnerabilities Let Attackers Execute Remote Code Microsoft Office Vulnerabilities Let Attackers Execute Remote Code Cyber Security News
Microsoft Patch for Old Flaw Reveals New Kernel Address Leak Vulnerability in Windows 11/Server 2022 24H2 Microsoft Patch for Old Flaw Reveals New Kernel Address Leak Vulnerability in Windows 11/Server 2022 24H2 Cyber Security News
OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites Cyber Security News
Cisco Small Business Switches Face Global DNS Crash Outage Cisco Small Business Switches Face Global DNS Crash Outage Cyber Security News
BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 Resolves Over 50 Security Flaws in Software
  • Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit
  • Seedworm Group Exploits Signed Binaries for Cyber Attacks
  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark