EDR-Freeze Tool Exploits Windows WER to Halt Defenses
A newly developed proof-of-concept known as the EDR-Freeze tool exploits Windows functionality by leveraging the Windows Error Reporting (WER) system to suspend security software directly from user mode. This technique raises concerns about the ability of threat actors to bypass endpoint detection and response (EDR) systems without requiring administrative privileges. The EDR-Freeze tool exploits Windows […]
