Title:Hacktool - EDR-Freeze Execution Status:experimental Description:Detects execution of EDR-Freeze, a tool that exploits the MiniDumpWriteDump function and WerFaultSecure.exe to suspend EDR and Antivirus processes on Windows.
EDR-Freeze leverages a race-condition attack to put security processes into a dormant state by suspending WerFaultSecure at the moment it freezes the target process.
This technique does not require kernel-level exploits or BYOVD, but instead abuses user-mode functionality to temporarily disable monitoring by EDR or Antimalware solutions.
References: -https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html -https://github.com/TwoSevenOneT/EDR-Freeze Author: Swachchhanda Shrawan Poudel (Nextron Systems) Date: 2025-09-24 modified:2025-11-27 Tags: