Tag
high
threat
Akira Ransomware Affiliate Abuses Safe Mode to Evade EDR
1 rule 2 TTPs 3 IOCsAn Akira ransomware affiliate gained initial access via a SonicWall VPN and attempted to evade security controls by rebooting the host into Safe Mode, an anti-EDR tactic that ultimately caused the ransomware to crash.
SonicWall SSL VPN +1
Akira
ransomware
edr-evasion
sonicwall
1r
2t
3i
high
advisory
Windows Bind Link Attacks Can Hide Malware From EDR Tools
3 TTPsBitdefender researchers revealed how attackers can exploit Windows bind links, a legitimate operating system feature, to create conflicting filesystem views that conceal malware from endpoint detection and response (EDR) tools and other security mechanisms, enabling post-compromise evasion despite requiring administrative privileges.
Windows
defense-evasion
edr-evasion
filesystem
3t
medium
advisory
Discussion of EDR Killers on Reddit
2 rules 2 TTPsA Reddit post on r/blueteamsec references an ESET WeLiveSecurity article discussing EDR killer techniques that extend beyond driver manipulation.
Endpoint Detection and Response
edr-evasion
defense-evasion
red-team
2r
2t