{"id":7096,"date":"2025-09-21T10:03:37","date_gmt":"2025-09-21T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/21\/new-edr-freeze-tool-that-puts-edrs-and-antivirus-into-a-coma-state\/"},"modified":"2025-09-21T10:03:37","modified_gmt":"2025-09-21T10:03:37","slug":"new-edr-freeze-tool-that-puts-edrs-and-antivirus-into-a-coma-state","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/21\/new-edr-freeze-tool-that-puts-edrs-and-antivirus-into-a-coma-state\/","title":{"rendered":"New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State"},"content":{"rendered":"<p>    New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Endpoint Detection and Response (EDR)<\/a> and antivirus solutions into a suspended \u201ccoma\u201d state.<\/p>\n<p>According to Zero Salarium, the technique leverages a built-in Windows function, offering a stealthier alternative to the increasingly popular <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-checkpoints-driver\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bring Your Own Vulnerable Driver (BYOVD)<\/a> attacks used by threat actors to disable security software.<\/p>\n<p>Unlike BYOVD methods, which require introducing a vulnerable driver onto a target system, EDR-Freeze exploits legitimate components of the Windows operating system.<\/p>\n<p>This approach avoids the need to install third-party drivers, reducing the risk of system instability and detection. The entire process is executed from user-mode code, making it a subtle and effective way to temporarily neutralize security monitoring.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-minidumpwritedump-exploit\"><strong>The MiniDumpWriteDump Exploit<\/strong><\/h2>\n<p>The core of the EDR-Freeze technique lies in the manipulation of the <code>MiniDumpWriteDump<\/code> function. This function, part of the Windows <code>DbgHelp<\/code> library, is designed to create a minidump, a snapshot of a process\u2019s memory for debugging purposes.<\/p>\n<p>To ensure a consistent and uncorrupted snapshot, the function suspends all threads within the target process while the dump is created.<\/p>\n<p>Ordinarily, this suspension is brief. However, the developer of EDR-Freeze devised a method to prolong this suspended state indefinitely.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjNZY2SS28D7gjcCEqqxwNqIU7sQsnticwCqVWhqIMpYxdNT7-Rr878zxluHU5E3EmW5KYrwds0bzUd6tCzX5w3sfjwDCHK06HzZoEF8gb8J31oUft5qPGtOFZ-iLi1y-HKIomH_OrQzi9OuHIjLy26vf_l9gZ83BqPAELR2ScCsVygHL277O35GE11l6gO\/s16000\/EDR-Freeze%2520running%2520parameters.webp?ssl=1\" alt=\"EDR-Freeze Tool\"><figcaption class=\"wp-element-caption\"><em>EDR-Freeze Tool<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The primary challenges were twofold: extending the very short execution time of the <code>MiniDumpWriteDump<\/code> function and bypassing the Protected Process Light (PPL) security feature that shields EDR and <a href=\"https:\/\/cybersecuritynews.com\/malware-analysis-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus<\/a> processes from tampering.<\/p>\n<p>To overcome PPL protection, the technique utilizes <code>WerFaultSecure.exe<\/code>, a component of the Windows Error Reporting (WER) service. <code>WerFaultSecure.exe<\/code> can run with <code>WinTCB<\/code> level protection, one of the highest privilege levels, allowing it to interact with protected processes.<\/p>\n<p>By crafting the correct parameters, <code>WerFaultSecure.exe<\/code> can be instructed to initiate the <code>MiniDumpWriteDump<\/code> function on any target process, including protected EDR and antivirus agents.<\/p>\n<p>The final piece of the puzzle is a race-condition attack that turns a momentary suspension into a prolonged freeze. The attack unfolds in a rapid, precise sequence:<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<code>WerFaultSecure.exe<\/code> is launched with parameters directing it to create a memory dump of the target EDR or antivirus process.<\/li>\n<li>The EDR-Freeze tool continuously monitors the target process.<\/li>\n<li>The moment the target process enters a suspended state (as <code>MiniDumpWriteDump<\/code> begins its work), the EDR-Freeze tool immediately suspends the <code>WerFaultSecure.exe<\/code> process itself.<\/li>\n<\/ol>\n<p>Because <code>WerFaultSecure.exe<\/code> is now suspended, it can never complete the memory dump operation and, crucially, can never resume the threads of the target EDR process.<\/p>\n<p>The result is that the security software is left in a permanent state of suspension, effectively blinded, until the <code>WerFaultSecure.exe<\/code> process is terminated, Zero Salarium <a href=\"https:\/\/www.zerosalarium.com\/2025\/09\/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">said<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-edr-freeze-tool-killing-process\"><strong>EDR-Freeze Tool Killing Process<\/strong><\/h2>\n<p>The developer has released the EDR-Freeze tool to demonstrate this technique. It takes two simple parameters: the Process ID (PID) of the target to be frozen and the duration of the suspension in milliseconds.<\/p>\n<p>This allows an attacker to disable <a href=\"https:\/\/cybersecuritynews.com\/iot-security-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a>, perform malicious actions, and then allow the security software to resume normal operations as if nothing had happened.<\/p>\n<p>A test on Windows 11 24H2 successfully suspended the <code>MsMpEng.exe<\/code> process of Windows Defender.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhxYfbeuBoP2xbYTedVbdO0ATBFs3tOZEZFFX4xiWZGX_yLwKUz9YNIq4xnRGpCushbWH_hogpt6htJipOXQ8vH6-mBNWUK9u_Tfp2KXQRwfh_D5k2nDAETGCzZfHOcfzI5LleVz3x52FRf13wTkQUfmeA6qpTCavb7E1wAvPOF3WUtBMqVpmoK70orzzvx\/s16000\/EDR-Freeze%2520can%2520suspend%2520MsMpEng%2520antimalware.webp?ssl=1\" alt=\"EDR-Freeze Tool Kills EDR and Antivirus\"><figcaption class=\"wp-element-caption\">EDR-Freeze Tool Kills EDR and Antivirus<\/figcaption><\/figure>\n<\/div>\n<p>For defenders, detecting this technique involves monitoring for unusual executions of <code>WerFaultSecure.exe<\/code>.<\/p>\n<p>If the program is observed targeting the PIDs of sensitive processes like <code>lsass.exe<\/code> or EDR agents, it should be treated as a high-priority security alert requiring immediate investigation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/edr-freeze-tool\/\">New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/edr-freeze-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New EDR-Freeze Tool That Puts EDRs and Antivirus Into A Coma State A new proof-of-concept tool named EDR-Freeze has been developed, capable of placing Endpoint Detection and Response (EDR) and antivirus solutions into a suspended \u201ccoma\u201d state. According to Zero Salarium, the technique leverages a built-in Windows function, offering a stealthier alternative to the increasingly [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,395],"tags":[130],"class_list":["post-7096","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7096"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7096"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7096\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}