{"id":8498,"date":"2025-11-16T10:00:15","date_gmt":"2025-11-16T10:00:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/16\/silentbutdeadly-network-communication-blocker-tool-that-neutralizes-edr-av\/"},"modified":"2025-11-16T10:00:15","modified_gmt":"2025-11-16T10:00:15","slug":"silentbutdeadly-network-communication-blocker-tool-that-neutralizes-edr-av","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/16\/silentbutdeadly-network-communication-blocker-tool-that-neutralizes-edr-av\/","title":{"rendered":"SilentButDeadly \u2013 Network Communication Blocker Tool That Neutralizes EDR\/AV"},"content":{"rendered":"<p>    SilentButDeadly \u2013 Network Communication Blocker Tool That Neutralizes EDR\/AV<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new open-source tool called SilentButDeadly has emerged, designed to disrupt <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">Endpoint Detection and Response (EDR)<\/a> and antivirus (AV) software by severing their network communications.<\/p>\n<p>Developed by security researcher Ryan Frami\u00f1\u00e1n, the tool leverages the Windows Filtering Platform (WFP) to create temporary, bidirectional blocks on EDR cloud connectivity, isolating threats without terminating processes. <\/p>\n<p>His approach builds on the 2023 EDRSilencer technique, offering improved operational safety through dynamic, self-cleaning filters.<\/p>\n<p>The tool addresses a key vulnerability in modern EDR architectures, which rely heavily on cloud-based telemetry for real-time analysis and updates. By preventing outbound data uploads and inbound command reception, SilentButDeadly effectively neuters remote management and threat intelligence sharing.<\/p>\n<p>Unlike aggressive evasion methods that disrupt security processes, it focuses on stealthy network isolation, making it ideal for <a href=\"https:\/\/cybersecuritynews.com\/red-team-exercise\/\">red-team<\/a> exercises and malware analysis in controlled environments. Frami\u00f1\u00e1n\u2019s implementation ensures no persistent artifacts remain unless explicitly configured, reducing forensic footprints.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-silentbutdeadly-execution\"><strong>SilentButDeadly Execution<\/strong><\/h2>\n<p>SilentButDeadly\u2019s execution unfolds in structured phases, beginning with privilege verification using Windows APIs like CheckTokenMembership() to confirm administrator access. Users are prompted interactively to proceed, enhancing control.<\/p>\n<p>The core discovery phase scans running processes via CreateToolhelp32Snapshot(), matching against a predefined list of EDR targets such as SentinelOne\u2019s SentinelAgent.exe and Microsoft Defender\u2019s MsMpEng.exe. Once identified, it queries full process paths and initializes WFP with a dynamic session flagged by FWPM_SESSION_FLAG_DYNAMIC for automatic cleanup.<\/p>\n<p>Network blocking is implemented at ALE layers: outbound via FWPM_LAYER_ALE_AUTH_CONNECT_V4 and inbound via FWPM_LAYER_ALE_AUTH_RECV_ACCEPT_V4, using high-priority weights (0x7FFF) and process-specific AppID conditions.<\/p>\n<p>Filters convert executable paths to WFP blobs with FwpmGetAppIdFromFileName0(), ensuring precise targeting. Following isolation, the tool disrupts services by stopping them gracefully and setting startup types to SERVICE_DISABLED, preventing restarts. A summary displays affected processes, block counts, and WFP status before optional cleanup removes all rules.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiZbIxFaRo0AqnhS5m_Uh9snYL_CETWl50dNlt1IOL_AYeKo9GzD3CnZvpD5owTJV37KuNh0y7x2LWFkKUGpC9i55mXQlpnuYa5MFi7nDS6c6tXzXHr10e950TMiYYLafHcAR3ZI7xn6etLPGiR5PrNRWnAsCq0sVpXobuYLDk3SmwruYjhhSvQxTJctBnn\/s16000\/EDR.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Supported targets include SentinelOne, Windows Defender, and Defender ATP (MsSense.exe), with extensibility via a simple array. Command-line options like \u2013verbose for logging and \u2013persistent for enduring filters add flexibility, while robust error handling provides graceful fallbacks.<\/p>\n<p>Security features emphasize legitimate APIs only, no kernel tweaks, though it requires admin rights. Operationally, it severs EDR updates, telemetry, and scans, but leaves local detection intact. Detection risks include WFP event logs (IDs 5441, 5157) and service modifications, detectable via netsh wfp commands or PowerShell queries.<\/p>\n<p>Frami\u00f1\u00e1n stresses ethical use for authorized testing, urging defenders to monitor WFP changes and implement resilient EDR designs with local caching.<\/p>\n<p>Available on <a href=\"https:\/\/github.com\/loosehose\/SilentButDeadly\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitHub<\/a> under loosehose\/SilentButDeadly, the tool sparks discussions on EDR dependencies, potentially driving vendor improvements. As cyber threats evolve, such research underscores the need for balanced architectures less reliant on constant connectivity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/silentbutdeadly-neutralizes-edr-av\/\">SilentButDeadly \u2013 Network Communication Blocker Tool That Neutralizes EDR\/AV<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/silentbutdeadly-neutralizes-edr-av\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SilentButDeadly \u2013 Network Communication Blocker Tool That Neutralizes EDR\/AV A new open-source tool called SilentButDeadly has emerged, designed to disrupt Endpoint Detection and Response (EDR) and antivirus (AV) software by severing their network communications. Developed by security researcher Ryan Frami\u00f1\u00e1n, the tool leverages the Windows Filtering Platform (WFP) to create temporary, bidirectional blocks on EDR [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-8498","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8498"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8498"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8498\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}