{"id":7962,"date":"2025-10-27T10:03:26","date_gmt":"2025-10-27T10:03:26","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/27\/new-edr-redir-tool-breaks-edr-exploiting-bind-filter-and-cloud-filter-driver\/"},"modified":"2025-10-27T10:03:26","modified_gmt":"2025-10-27T10:03:26","slug":"new-edr-redir-tool-breaks-edr-exploiting-bind-filter-and-cloud-filter-driver","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/27\/new-edr-redir-tool-breaks-edr-exploiting-bind-filter-and-cloud-filter-driver\/","title":{"rendered":"New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver"},"content":{"rendered":"<p>    New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new tool called EDR-Redir has emerged, allowing attackers to redirect or isolate the executable folders of popular Endpoint Detection and Response (EDR) solutions.<\/p>\n<p>Demonstrated by cybersecurity researcher TwoSevenOneT, the technique leverages Windows\u2019 Bind Filter driver (bindflt.sys) and Cloud Filter driver (cldflt.sys) to undermine EDR protections without requiring kernel-level access.<\/p>\n<p>This user-mode exploit, rooted in the Bring Your Own Vulnerable Driver (<a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-checkpoints-driver\/\" target=\"_blank\" rel=\"noreferrer noopener\">BYOVD<\/a>) approach, could enable attackers to disable defenses, inject malicious code, or hijack processes, leaving systems vulnerable to undetected intrusions.<\/p>\n<p>The vulnerability stems from Windows 11\u2019s Bind Link feature, introduced in <a href=\"https:\/\/cybersecuritynews.com\/windows-11-24h2-update-video\/\" target=\"_blank\" rel=\"noreferrer noopener\">version 24H2<\/a>. Bind Links provide filesystem namespace redirection via virtual paths, managed by the bindflt.sys minifilter driver.<\/p>\n<p>Unlike traditional symbolic links, which EDRs actively monitor and block using mechanisms like Microsoft\u2019s RedirectionGuard, Bind Links operate transparently at the driver level.<\/p>\n<p>They map virtual paths to real ones, local or remote, without creating physical files, inheriting permissions from the target while remaining invisible to most applications.<\/p>\n<p>This subtlety allows attackers with administrator privileges to perform read and open operations on protected EDR folders, which are typically locked against writes.<\/p>\n<p>EDR-Redir, available as an open-source tool on <a href=\"https:\/\/github.com\/TwoSevenOneT\/EDR-Redir\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub<\/a>, simplifies the process with straightforward commands. For instance, running \u201cEDR-Redir.exe bind C:TMP123 C:TMP456\u201d creates a virtual path at C:TMP123 that redirects all interactions to C:TMP456.<\/p>\n<p>The researcher <a href=\"https:\/\/www.zerosalarium.com\/2025\/10\/DR-Redir-Break-EDR-Via-BindLink-Cloud-Filter.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tested<\/a> this against multiple EDRs. With Elastic Defend and Sophos Intercept X, the tool successfully redirected their executable folders to attacker-controlled locations.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrh4P7YPayHK_KeJFU2Ti8rwPWsOqOfF1le133CLkQnw2Q2TuaQ58xll496AtOVXUSCNmVuZSyQ_14xHp62l9EhUwQraz56XCi83KwMiI8xQK6E6Y-iiwuLjfIRjqR1LPly2FZPpJF2bEDbvwqGhcsodEd-3Wois7CFsvYS7gBsb9SrZflqaXvImkgHm__\/s16000\/Sophos%2520inter.webp?ssl=1\" alt=\"Sophos EDR Break\"><figcaption class=\"wp-element-caption\">Sophos EDR Break<\/figcaption><\/figure>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi4SphRR5Ld7eLoDmoPVFS__NSRU9pjYLgg-AzDw1adeVGgYkhfd3EumfMNGNQMXUYzOCo0Ru2PTjyVtdTzI2cErtgcLXsEM9EvydOrtjwbBKJtodL0JNjpJgk6FIRIqln5CN_-AxJtJ1Q6qpEN4EDS3-tgE1U476bNZ7m13Wk3jshh0AoxOFKBAQKMQv7k\/s16000\/Elastic%2520EDR.webp?ssl=1\" alt=\"Elastic EDR\"><figcaption class=\"wp-element-caption\">Elastic EDR<\/figcaption><\/figure>\n<\/div>\n<p>Once redirected, adversaries could drop DLLs for process hijacking, insert malicious executables, or empty the folder to halt EDR operations on reboot. Notably, these Bind Links do not persist across restarts, requiring a scheduled task or service for automation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-bypassing-windows-defender-with-cloud-filter-tricks\"><strong>Bypassing Windows Defender with Cloud Filter Tricks<\/strong><\/h2>\n<p>Windows Defender proved more resilient to direct Bind Link redirection, likely due to its integrated protections. However, the researcher devised a workaround using the Cloud Files API (CFAPI), powered by cldflt.sys.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEijSgVWw66jO0zHh2LBINECKgBo2NLOjTG9ZgZNprJC1YLPPoPbNDbMp5qLDwVVdjsMWxluHrQyu1uPVH4oB26JfRjz77iU3F9UPmLY17ApsTFsE7qlDkjZW6vuANgqIHsjml_X9jyTCKC5G8tRLGvuDeG0_Ej8kFI4_joMZrqEuJk4znsqIDdkG5sFe7QM\/s16000\/Corrupted%2520sync%2520root%2520folder%2520with%2520EDR-Redir.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Sync Fail<\/figcaption><\/figure>\n<p>This API, designed for sync engines like <a href=\"https:\/\/cybersecuritynews.com\/onedrive-auto-sync-secrets-sharepoint\/\" target=\"_blank\" rel=\"noreferrer noopener\">OneDrive<\/a>, enables on-demand file access through placeholder files. By invoking CfRegisterSyncRoot with minimal policies essentially an incomplete registration EDR-Redir registers the Defender folder as a \u201csync root.\u201d<\/p>\n<p>This corrupts access, preventing the EDR from reading or writing to its directory. Post-reboot, Defender\u2019s services fail to start, effectively isolating it.<\/p>\n<p>Unlike Bind Links, this Cloud Filter method persists without additional setup, making it particularly stealthy. A demo video shared by the researcher illustrates the process, showing Defender\u2019s folder becoming inaccessible after registration.<\/p>\n<p>Tests confirmed similar efficacy against two unnamed commercial <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDRs<\/a>, highlighting a broad risk.<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"EDR-Redir Breaking EDR Via Bind Link and Cloud Filter\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/2_tanx7RSUw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div>\n<\/figure>\n<p>This technique underscores a growing challenge: EDRs must evolve beyond user-mode symlink defenses to scrutinize minifilter interactions. Attackers gain full control over EDR behaviors, potentially evading detection in red-team exercises or real breaches.<\/p>\n<p>Organizations should audit administrator privileges, monitor for unusual driver loads, and apply Windows patches promptly. Vendors like Microsoft, Elastic, and Sophos are urged to enhance folder protections against these API abuses.<\/p>\n<p>As endpoint threats intensify, tools like EDR-Redir remind us that even robust defenses can falter on overlooked filesystem features.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/edr-redir-tool-breaks-edr\/\">New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/edr-redir-tool-breaks-edr\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver A new tool called EDR-Redir has emerged, allowing attackers to redirect or isolate the executable folders of popular Endpoint Detection and Response (EDR) solutions. Demonstrated by cybersecurity researcher TwoSevenOneT, the technique leverages Windows\u2019 Bind Filter driver (bindflt.sys) and Cloud Filter driver (cldflt.sys) to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7962","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7962"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7962"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7962\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}