Skip to main content

Threats Tagged 'edr killer'

View all threats tagged with 'edr killer'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: edr killer

Threats Tagged 'edr killer'

Click on any threat for detailed analysis and mitigation recommendations

The Gentlemen ransomware group, which emerged in July 2025, employed a zero-day vulnerability in a bring-your-own-vulnerable-driver (BYOVD) attack to disable endpoint detection and response systems. During an incident investigated in early April, the group leveraged an obscure third-party driver named ktapi.sys from Kontron to bypass security protections. The sophisticated exploit chains multiple advanced techniques to navigate Windows exploit mitigations, including bypassing Supervisor Mode Access Prevention and Supervisor Mode Execution Prevention. The toolkit enables the attackers to call privileged kernel mode functions from user mode processes, ultimately terminating EDR processes including Windows Defender, ESET, Palo Alto Cortex XDR, and SentinelOne. The vulnerability had no prior public documentation and was previously absent from vulnerable driver blocklists.

Join the discussion

In early February 2026, an intrusion was detected where threat actors exploited compromised SonicWall SSLVPN credentials for initial network access. The attackers deployed an EDR killer utilizing a legitimate but revoked EnCase forensic driver to terminate security processes from kernel mode. This technique, known as Bring Your Own Vulnerable Driver (BYOVD), bypasses Windows Driver Signature Enforcement. The attack was halted before ransomware deployment, but it highlights the growing trend of weaponizing signed, legitimate drivers to disable endpoint security. The intrusion involved aggressive network reconnaissance, deployment of a sophisticated EDR killer with an encoded kernel driver payload, and attempts to establish persistence. The case underscores the importance of multi-factor authentication, VPN log monitoring, and implementing Microsoft's recommended driver block rules.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: edr killer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses