{"id":8127,"date":"2025-11-02T10:03:28","date_gmt":"2025-11-02T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/02\/new-edr-redir-v2-blinds-windows-defender-on-windows-11-with-fake-program-files\/"},"modified":"2025-11-02T10:03:28","modified_gmt":"2025-11-02T10:03:28","slug":"new-edr-redir-v2-blinds-windows-defender-on-windows-11-with-fake-program-files","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/02\/new-edr-redir-v2-blinds-windows-defender-on-windows-11-with-fake-program-files\/","title":{"rendered":"New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files"},"content":{"rendered":"<p>    New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An upgraded release of tool EDR-Redir V2, designed to evade Endpoint Detection and Response (EDR) systems by exploiting Windows bind link technology in a novel way.<\/p>\n<p>According to the researcher TwoSevenOneT, the version targets the parent directories of EDR installations, such as Program Files, to create redirection loops that blind security software without disrupting legitimate applications.<\/p>\n<p>Previously, <a href=\"https:\/\/cybersecuritynews.com\/edr-redir-tool-breaks-edr\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR-Redir<\/a> used direct folder redirections, but protections often blocked those attempts; V2 circumvents this by looping subfolders back to themselves while isolating the EDR\u2019s path for manipulation.\u200b<\/p>\n<p>The tool builds on Windows\u2019 bind link feature, introduced in <a href=\"https:\/\/cybersecuritynews.com\/windows-11-24h2-update-issue\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows 11 24H2<\/a>, which allows filesystem namespace redirection via the bindflt.sys driver without kernel privileges.<\/p>\n<p>EDR solutions like antivirus programs typically lock down their subfolders in locations such as Program Files or ProgramData to prevent tampering, but they cannot fully restrict writes to parent directories without breaking system installations.<\/p>\n<p>EDR-Redir V2 queries all subfolders in the target parent, like Program Files, and mirrors them in a controlled directory, such as C:TMPTEMPDIR. It then establishes bidirectional bind links between these mirrors and originals, forming loops that maintain normal access for non-EDR software.<\/p>\n<p>The EDR\u2019s specific subfolder, such as Windows Defender\u2019s in C:ProgramDataMicrosoft, is excluded from the loop and redirected solely to the attacker\u2019s TEMPDIR.<\/p>\n<p>This setup enables <a href=\"https:\/\/cybersecuritynews.com\/notepad-hijacking-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL hijacking<\/a> or file drops in the redirected space, tricking the EDR into loading malicious components. Developers often overlook such parent-level redirections, potentially affecting a wide range of EDRs.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"testing-edr-redir-v2-on-windows-defender\"><strong>EDR-Redir V2 on Windows Defender<\/strong><\/h2>\n<p>In a demonstration on Windows 11, TwoSevenOneT applied EDR-Redir V2 against <a href=\"https:\/\/cybersecuritynews.com\/windows-defender\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a>, located in C:ProgramDataMicrosoftWindows Defender.<\/p>\n<p>The tool was executed with parameters specifying the target folder, redirection destination, and exception path: EDR-Redir.exe C:ProgramDataMicrosoft c:TMPTEMPDIR \u201cC:ProgramDataMicrosoftWindows Defender\u201d.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjJ8OaUa8f4ZaJUlNRJ0hS2jUidmG2bkEyCL-WdH_Z1fOAC4QnyYUaY7wgCwEdxa_GwMEC903GAFLe0hdv5ZKk7kMyhTToJFFJXdIkGyeTWA1s3l8Z4rI9PeJomG5t_oDCi-sqbmyraynLq0OSXiN03uRBk8wVoIvCNyKHwld2aFe6GOD_IWoc6hyphenhyphenNfygFW\/s16000\/EDR-Redir%2520V2%2520run%2520successfully%2520with%2520Windows%2520Defender%2520%281%29.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Console output detailed the bind link creations, confirming success without errors. Post-execution, Defender\u2019s access attempts looped through TEMPDIR, effectively blinding it to its original files and allowing potential evasion tactics.<\/p>\n<p>A visualization showed the redirection in action, with Defender viewing TEMPDIR as its operational parent. The GitHub repository for EDR-Redir provides the tool for download and further testing. A demo video on YouTube illustrates the process in real-time.\u200b<\/p>\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"EDR REDIR V2 Blind EDR With Fake Program Files\" width=\"696\" height=\"392\" src=\"https:\/\/www.youtube.com\/embed\/PbXPChdWy3E?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div>\n<\/figure>\n<p>This technique highlights vulnerabilities in how EDRs protect against filesystem manipulations at the parent level, rendering folder-specific safeguards ineffective. Attackers could disable EDR services or inject code, operating undetected in user mode with minimal events.<\/p>\n<p>While no widespread exploits are reported yet, the method\u2019s simplicity raises concerns for enterprise environments. Defenders should monitor bind link usage in critical directories like Program Files and implement integrity checks on EDR paths.<\/p>\n<p>EDR vendors may need to enhance protections for parent folders without impeding usability. TwoSevenOneT shares ongoing research on X (@TwoSevenOneT) for pentesting insights. As evasion tools evolve, proactive monitoring of kernel filters remains essential.\u200b<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/edr-redir-v2-blinds-windows-defender\/\">New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/edr-redir-v2-blinds-windows-defender\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files An upgraded release of tool EDR-Redir V2, designed to evade Endpoint Detection and Response (EDR) systems by exploiting Windows bind link technology in a novel way. According to the researcher TwoSevenOneT, the version targets the parent directories of EDR installations, such as [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,395],"tags":[130],"class_list":["post-8127","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8127"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8127"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8127\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}