Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomware

EDR-Freeze

EDR-Freeze is a driverless EDR/AV evasion tool and technique that abuses built-in Windows debugging mechanisms in user mode to temporarily suspend endpoint detection and response and antivirus processes, causing them to hang or become unresponsive. The content states it leverages Windows internals including MiniDumpWriteDump and WerFaultSecure.exe, and detections specifically monitor WerFaultSecure.exe loading dbgcore.dll and dbghelp.dll and accessing security processes such as MsMpEng.exe. It is described as an alternative to BYOVD-style EDR killers because it does not require loading a vulnerable third-party driver. ESET identified EDR-Freeze as part of an emerging class of driverless EDR killers being adopted quickly by ransomware actors and used as a pre-encryption defense-evasion component in modern ransomware intrusions. The tool is associated in the content with security researcher TwoSevenOneT, who is also noted for EDR-Redir and EDRStartupHinder. High-confidence detection-related indicators mentioned in the content include WerFaultSecure.exe, dbgcore.dll, dbghelp.dll, access to EDR processes including MsMpEng.exe, and updated hacktool detections with a new executable name and new IMPHASH values, though the specific values are not provided.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

1 technique
T1218System Binary Proxy ExecutionEvidence1

EDR-Freeze ... WerFaultSecure.exeの仕様を悪用し、BYOVDを使わずにユーザーモードでEDR/アンチマルウェアプロセスを一時停止(coma状態)にするツール。

Other

2 techniques
T1562Impair DefensesEvidence2

Tools like EDRSilencer and EDR-Freeze do not need to interact with the system kernel at all. Instead, they block network communication between the endpoint and the security backend, or they force the EDR software to freeze in place. | Before launching their file-encrypting malware, cybercriminals routinely deploy specialized tools to bypass security software... Attackers are now heavily using driverless methods, custom command-line scripts, and legitimate anti-rootkit utilities to turn off security defenses.

T1562.001Disable or Modify ToolsEvidence2

EDR killers terminate or suspend EDR/AV processes and services to bypass detection.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.