EDRSilencer is a Windows driverless EDR-killer / security-solution tampering tool designed to impair endpoint detection and response products without terminating their processes. Instead of killing the agent, it blocks the product’s outbound network communication so telemetry cannot reach the security backend, effectively pushing the EDR into a degraded or "coma-like" state while leaving the process running. The tool is described as inspired by MdSec NightHawk’s closed-source FireBlock and uses Windows Filtering Platform (WFP) APIs to identify running EDR processes and apply outbound traffic-blocking filters. Reported functionality includes adding filters for specific processes, removing filters individually or globally, and a custom CreateFileW bypass to avoid file-handle access issues with EDR processes. The referenced content states it supports multiple EDR products, including Microsoft Defender, Carbon Black, and SentinelOne, and has been tested on Windows 10 and Windows Server 2016.
The tool has been highlighted by ESET as part of an emerging class of driverless EDR killers that ransomware actors are adopting quickly. In that context, EDRSilencer is associated with modern ransomware intrusion workflows as a pre-encryption defense-evasion component used to neutralize security tooling before payload deployment. The content does not attribute EDRSilencer to a specific threat actor, but places it within the broader ecosystem of EDR-killer tooling used by ransomware affiliates and operators.
Detection guidance in the provided content includes Splunk analytics for execution of EDRSilencer.exe and command-line patterns containing "blockedr" while excluding "blockedreport." The content also references a public GitHub repository for the tool at github.com/netero1010/EDRSilencer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
When these firewall rules are created, they’re actually stored in the registry under: HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{GUID}... When filters are set, they’re stored in the registry just like firewall rules, just in a different location.
When these firewall rules are created, they’re actually stored in the registry under: HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\{GUID}... When filters are set, they’re stored in the registry just like firewall rules, just in a different location.
Once kernel privileges are confirmed, the killer enumerates a hardcoded list of EDR product names, service names, driver names, and process names, and tears each one down.
EDR killers terminate or suspend EDR/AV processes and services to bypass detection.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An EDR evasion tool that suppresses telemetry by blocking the endpoint agent’s network communications instead of terminating the agent process.
A Windows tool used to impair or silence EDR products by locating running EDR processes and applying Windows Filtering Platform filters to block their outbound traffic. It can add or remove filters and includes a custom method to bypass CreateFileW-related handle access issues.
A driverless EDR killer that blocks outbound traffic from EDR products, causing them to become ineffective or enter a coma-like state.
Driverless EDR killer that blocks communication between the endpoint and the security backend to impair defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.