{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/edr-silencing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["defense-evasion","edr-silencing","windows-filtering-platform"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries are increasingly abusing the Windows Filtering Platform (WFP) to disrupt the operations of security products. Tools such as EDRSilencer leverage the legitimate capabilities of WFP to dynamically inject filter rules that explicitly block outbound network traffic originating from security agent processes. By creating these block filters, attackers can effectively disable the reporting functionality of EDRs, antivirus solutions, and logging agents without needing to terminate the processes themselves. This technique allows for stealthier persistence of malicious activity, as the security agent remains active in the process list but fails to communicate threat telemetry to central consoles. Defenders must monitor WFP policy modifications for unauthorized block rules targeting security binaries to mitigate this evasion technique.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains administrative or elevated privileges on the target Windows system.\u003c/li\u003e\n\u003cli\u003eThe attacker deploys a tool, such as EDRSilencer, capable of interacting with the Windows Filtering Platform API.\u003c/li\u003e\n\u003cli\u003eThe tool enumerates running processes to identify security agents (e.g., MsMpEng.exe, xagt.exe, CylanceSvc.exe).\u003c/li\u003e\n\u003cli\u003eThe tool constructs a WFP filter rule designed to drop network packets associated with the identified target processes.\u003c/li\u003e\n\u003cli\u003eThe tool interacts with the WFP engine via administrative APIs to commit the new filter rule with a \u0026quot;Block\u0026quot; action.\u003c/li\u003e\n\u003cli\u003eThe target EDR process continues to run but is prevented from transmitting telemetry to its cloud or management server.\u003c/li\u003e\n\u003cli\u003eThe attacker conducts follow-on malicious activity while the EDR remains effectively silenced.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of this technique results in the complete loss of visibility into host-based security telemetry. By silencing agents, an attacker can operate on an endpoint undetected, potentially leading to unauthorized data exfiltration, lateral movement, or ransomware deployment without triggering standard security alerts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Windows Security Event Log auditing for Event ID 5447 (Windows Filtering Platform) to capture WFP policy changes.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to identify the creation of block filters targeting known security processes.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline for authorized administrative tools that modify WFP filters; investigate any processes outside of this baseline performing such actions.\u003c/li\u003e\n\u003cli\u003eIntegrate Event ID 5447 into your SIEM monitoring to alert on any WFP rule addition with a \u0026quot;Block\u0026quot; action.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T15:46:36Z","date_published":"2026-08-24T15:46:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wfp-edr-silencing/","summary":"Adversaries are utilizing the Windows Filtering Platform (WFP) to create block filters that silence security agent communications, preventing the delivery of telemetry and evading detection.","title":"Abuse of Windows Filtering Platform to Disable EDR Telemetry","url":"https://feed.craftedsignal.io/briefs/2026-08-wfp-edr-silencing/"}],"language":"en","title":"CraftedSignal Threat Feed - Edr-Silencing","version":"https://jsonfeed.org/version/1.1"}