Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity

The open-source EDRSilencer program is being abused by threat actors in an attempt to tamper with endpoint detection and response (EDR) solutions and conceal harmful activities.

Trend Micro claimed to have identified “threat actors attempting to integrate EDRSilencer in their attacks, repurposing it as a means of evading detection.”

EDRSilencer uses the Windows Filtering Platform (WFP) to restrict outgoing traffic from running EDR processes. It was inspired by the NightHawk FireBlock tool from MDSec.

Terminating different EDR product-related processes is supported by Palo Alto Networks read more about Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *