HackTool - EDRSilencer Execution - Filter Added

 Original Source: [Sigma source]
Title: HackTool - EDRSilencer Execution - Filter Added
Status: test
Description:Detects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.
References:
  -https://github.com/netero1010/EDRSilencer
Author: Thodoris Polyzos (@SmoothDeploy)
Date: 2024-01-29
modified:2024-01-30
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Filtering Platform Policy Change needs to be enabled
Detection:
  selection:
    EventID:
      -'5441'
      -'5447'

    FilterName|contains: 'Custom Outbound Filter'
  condition:selection
Falsepositives:
  -Unknown
Level: high