Files
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00

680 lines
42 KiB
YAML

Name: EDR Bypass Techniques
Id: 698a1587-aa31-4b93-96ac-baa05bff2cfe
MitreIds:
- T1562.001
- T1562.006
- T1055.001
- T1014
Tactics:
- Defense Evasion
Techniques:
- 'Impair Defenses: Disable or Modify Tools'
- 'Impair Defenses: Indicator Blocking'
- 'Process Injection: Dynamic-link Library Injection'
- Rootkit
DetectionPriority: CRITICAL
ThreatPrevalence: HIGH
DetectionDifficulty: HIGH
Description: 'Adversaries impair or neutralize EDR/AV products before executing their primary payload to prevent detection
and response. Techniques span from user-mode API unhooking (removing hooks EDRs inject into ntdll.dll) through kernel-level
driver exploitation (BYOVD, Bring Your Own Vulnerable Driver) to direct process termination of security tools. Despite
the diversity of techniques, the chokepoint is invariant: admin/SYSTEM privileges are always required, and the bypass mechanism
always produces a kernel-observable artifact - a driver load event, a VirtualProtect call against protected system memory,
or direct termination of a security process. BYOVD is now a de facto phase in major ransomware deployment chains.
'
LastUpdated: '2026-03-12'
Author: '@iimp0ster'
Variations:
- Name: BYOVD - EDRKillShifter
FirstSeen: 2024-Q3
Status: Active
SourceURL: https://www.sophos.com/en-us/blog/edr-kill-shifter/
NotesShort: RansomHub Go-based loader; decrypts embedded driver with 64-char password
Notes: 'Deployed by RansomHub (August 2024); Go-based loader that decrypts an embedded payload and exploits multiple vulnerable
kernel drivers in sequence to remove EDR callbacks. Subsequently adopted by Play, Medusa, and BianLian. Requires admin
privileges and a password string to decrypt the embedded driver payload.'
VariantId: byovd-edrkillshifter
Command:
Invocation: 'EDRKillShifter.exe <64-char-password-string>'
Context: 'Deployed as a pre-ransomware step. Attacker already has admin privileges. Password decrypts embedded vulnerable
driver payload. Second stage uses self-modifying code (runtime instruction rewriting).'
Artifacts:
- 'Sysmon EID 11: .sys file written to %TEMP% with random 4-10 char name'
- 'Sysmon EID 6: Unsigned or newly signed driver loaded'
- 'Sysmon EID 1: EDRKillShifter.exe (or renamed) with long password argument'
- 'Windows System EID 7045: New service installed for the dropped driver'
- 'Process termination of EDR processes (MsMpEng.exe, CSFalconService.exe, etc.)'
ChokepointMapping: 'admin privileges → driver written to TEMP → driver loaded as service (EID 6) → EDR process termination'
- Name: BYOVD - Terminator (Spyboy)
FirstSeen: 2023-Q1
Status: Active
SourceURL: https://www.sentinelone.com/blog/terminator-edr-killer-spyboy-detecting-and-preventing-a-windows-byovd-attack/
NotesShort: Sold on RAMP forum; exploits Zemana zam64.sys to kill 23+ EDR/AV products
Notes: 'Sold on Russian forum RAMP for $300-$3,000; exploits vulnerable Zemana antimalware driver (zam64.sys, CVE-2022-42045) to kill 23+ EDR/AV products including CrowdStrike, Sophos, Defender, ESET, and Kaspersky. Open-source
clones (SharpTerminator, Ternimator) widely available by 2024.'
VariantId: byovd-terminator-spyboy
Command:
Invocation: "Terminator.exe\n \u2192 drops zam64.sys as C:\\Windows\\System32\\drivers\\<random>.sys\n \u2192 sc create
<random_name> type=kernel binPath=C:\\Windows\\System32\\drivers\\<random>.sys\n \u2192 sc start <random_name>\n \u2192
IOCTL 0x80002010 (register PID as trusted)\n \u2192 IOCTL to terminate target PIDs"
Context: 'Requires admin privileges and UAC acceptance. Drops the legitimate Zemana anti-malware driver with a randomized
filename to System32\drivers.'
Artifacts:
- 'Sysmon EID 11: zam64.sys content written with random filename to System32\drivers'
- 'Sysmon EID 6: Driver loaded, signed by "Zemana Ltd."'
- 'Windows System EID 7045: New kernel service created'
- 'Sysmon EID 1: Process creation with admin/SYSTEM context'
- 'Multiple EDR process terminations in rapid succession'
ChokepointMapping: 'admin + UAC acceptance → Zemana driver dropped to System32 → driver loaded as service (EID 6) → IOCTL-based EDR process kill'
- Name: BYOVD - AuKill
FirstSeen: 2023-Q1
Status: Active
SourceURL: https://www.sophos.com/en-us/blog/aukill-edr-killer-malware-abuses-process-explorer-driver/
NotesShort: Abuses Process Explorer driver v16.32; observed in Medusa Locker and LockBit
Notes: 'Uses Microsoft Process Explorer driver v16.32 (PROCEXP.SYS). Observed in Medusa Locker and LockBit ransomware
deployments since January 2023. Based on the open-source Backstab tool.'
VariantId: byovd-aukill
Command:
Invocation: "AuKill.exe startkey\n \u2192 copies self to C:\\Windows\\System32\\\n \u2192 drops PROCEXP.SYS to
C:\\Windows\\System32\\drivers\\\n \u2192 impersonates TrustedInstaller.exe for SYSTEM escalation\n \u2192 sc create
/ sc start for PROCEXP driver\n \u2192 enters loop: TerminateViaProcexp() against EDR PIDs"
Context: 'Checks for admin rights; if not SYSTEM, impersonates TrustedInstaller. V6+ also unloads EDR drivers to
break installation completely.'
Artifacts:
- 'Sysmon EID 11: PROCEXP.SYS written to System32\drivers (legitimate PE signed by Microsoft)'
- 'Sysmon EID 6: Process Explorer driver loaded (v16.32, not current v152)'
- 'Sysmon EID 1: AuKill process with "startkey" command-line argument'
- 'Sysmon EID 1: TrustedInstaller impersonation activity'
- 'Windows System EID 7045: Service install for PROCEXP driver'
- 'Windows System EID 7036: EDR services transitioning to stopped state'
ChokepointMapping: 'admin → TrustedInstaller impersonation → PROCEXP.SYS dropped and loaded (EID 6) → EDR processes and services terminated'
- Name: BYOVD - POORTRY / STONESTOP
FirstSeen: 2022-Q4
Status: Active
SourceURL: https://www.sophos.com/en-us/blog/burnt-cigar-2/
NotesShort: Purpose-built malicious driver with stolen certs; EDR wiper capability since 2024
Notes: 'Custom-built kernel driver (POORTRY) with dedicated userland loader (STONESTOP). Not a repurposed vulnerable
driver. It is a purpose-built malicious driver signed with stolen/forged certificates. Used by Cuba, BlackCat, Medusa, LockBit,
RansomHub. Evolved from process termination to full EDR file wiping in 2024.'
VariantId: byovd-poortry-stonestop
Command:
Invocation: "Stonestop.exe (packed with ASMGuard/VMProtect/Themida)\n \u2192 drops POORTRY driver (masquerades as
idmtdi.sys / Internet Download Manager)\n \u2192 driver signed with stolen cert (rotates: \"bopsoft\", \"Evangel
Technology\", \"FEI XIAO\", etc.)\n \u2192 sends IOCTLs to:\n a) Remove kernel notify callbacks\n b) Terminate
EDR processes\n c) Delete EDR files from disk (2024+ capability)"
Context: 'Certificate roulette: multiple variants with different certs deployed in same attack. 2024+: deletes EDR
executable files and DLLs from disk. Operates in two deletion modes: by file type or by specific filename.'
Artifacts:
- 'Sysmon EID 11: Driver file dropped, masquerading as legitimate software driver'
- 'Sysmon EID 6: Driver loaded with non-standard or recently issued certificate'
- 'Windows System EID 7045: Service created for malicious driver'
- 'Windows System EID 7034: EDR service terminated unexpectedly'
- 'Sysmon EID 23/26: File deletion events for EDR components'
- 'Security EID 4616: System time changed (timestamp forging for DSE bypass)'
ChokepointMapping: 'admin → Stonestop drops POORTRY driver → driver loaded with forged/stolen cert (EID 6) → kernel callbacks removed → EDR processes killed → EDR files deleted'
- Name: Kernel Callback Removal (EDRSandblast)
FirstSeen: 2022-Q1
Status: Active
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
NotesShort: Removes kernel callbacks without killing EDR processes. EDR runs blind.
Notes: 'Directly removes registered kernel callbacks (PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine) from
the kernel callback array, blinding EDRs at the kernel level without killing their processes. Uses hardcoded kernel
offsets to avoid BSOD. Absence of expected callbacks is detectable via memory analysis.'
VariantId: kernel-callback-removal-edrsandblast
Command:
Invocation: "EDRSandblast.exe [--usermode | --kernelmode | --all]\n \u2192 uses ntoskrnl.exe offsets database to
locate callback arrays\n \u2192 patches PsSetCreateProcessNotifyRoutine callbacks\n \u2192 patches
PsSetLoadImageNotifyRoutine callbacks\n \u2192 patches CmRegisterCallback callbacks\n \u2192 optionally unhooks
SSDT entries"
Context: 'EDR processes continue running but receive no kernel notifications. No process termination events -
EDR stays alive but blinded.'
Artifacts:
- 'Sysmon EID 6: Vulnerable driver loaded (used for kernel R/W)'
- 'Sysmon EID 1: EDRSandblast execution with --kernelmode or --all flags'
- 'Memory analysis: Absence of expected kernel callbacks (PsNotifyRoutine array zeroed)'
- 'No process termination events. EDR processes stay alive but blinded.'
ChokepointMapping: 'admin → vulnerable driver loaded for kernel R/W → kernel callback arrays patched → EDR blinded (no process/image notifications)'
- Name: PPL Abuse (PPLKiller / PPLdump)
FirstSeen: 2020-Q4
Status: Active
SourceURL: https://github.com/RedCursorSecurityConsulting/PPLKiller
NotesShort: Strips Protected Process Light attribute from security processes
Notes: 'Protected Process Light (PPL) guards LSA and security processes from user-mode attacks. PPLKiller uses a kernel
driver to strip PPL protection, enabling termination of EDR processes and LSASS dumping even with RunAsPPL enabled.
PPLdump was patched by Microsoft; PPLKiller and Ghost-in-the-PPL variants remain active.'
VariantId: ppl-abuse-pplkiller-ppldump
Command:
Invocation: "PPLKiller.exe /installDriver\nPPLKiller.exe /disablePPL <target_pid>\nPPLKiller.exe /dumpProcess
<target_pid>"
Context: 'Requires kernel-level access (typically via BYOVD). Modifies the _PS_PROTECTION field in the target
process EPROCESS structure to remove PPL flag.'
Artifacts:
- 'Sysmon EID 6: Vulnerable driver loaded'
- 'Sysmon EID 1: PPLKiller/PPLdump execution with PID argument'
- 'Sysmon EID 10: Process access to formerly-protected process with full access rights'
- 'Process termination of PPL-protected EDR process'
ChokepointMapping: 'admin → vulnerable driver for kernel R/W → PPL flag stripped from EPROCESS → EDR process terminated or dumped'
- Name: User-mode Unhooking (ntdll Fresh Copy)
FirstSeen: 2020-Q1
Status: Active
SourceURL: https://www.ired.team/offensive-security/defense-evasion/how-to-unhook-a-dll-using-c++
NotesShort: Loads clean ntdll.dll from disk to bypass EDR userland hooks
Notes: 'EDRs inject hooks into ntdll.dll at process startup to intercept syscalls. Attackers restore the original (unhooked)
ntdll.dll by reading a clean copy from a suspended process or directly from disk, then overwriting the hooked version.
Eliminates all user-mode EDR visibility without touching the kernel.'
VariantId: user-mode-unhooking-ntdll-fresh-copy
Command:
Invocation: "# Embedded in malware. No standalone CLI.\nntdll_base = LoadLibraryEx(\"C:\\\\Windows\\\\System32\\\\ntdll.dll\",
LOAD_LIBRARY_AS_DATAFILE)\n# Overwrite .text section of hooked ntdll with clean copy"
Context: 'Technique is embedded in malware code, not a standalone tool. Kernel-level ETW Threat-Intelligence providers
still fire on sensitive operations.'
Artifacts:
- 'Sysmon EID 7: Second ntdll.dll loaded into process memory'
- 'ETW: Microsoft-Windows-Kernel-Process shows unusual syscall patterns'
- 'Memory analysis: Process with two ntdll.dll mappings or modified .text section'
ChokepointMapping: 'malware execution → fresh ntdll.dll loaded or direct syscalls → EDR userland hooks bypassed'
- Name: Direct and Indirect Syscalls (SysWhispers, Hell's Gate, Halo's Gate)
FirstSeen: 2019-Q3
Status: Active
SourceURL: https://github.com/jthuraisamy/SysWhispers
NotesShort: Bypass userland hooks via direct kernel syscall invocation
Notes: 'Bypass user-mode EDR hooks by invoking Windows kernel syscalls directly without passing through ntdll.dll hook stubs.
Direct syscalls embed syscall instructions in attacker code; indirect syscalls jump to the syscall instruction inside
ntdll for a legitimate call stack appearance. SysWhispers3 (2022) adds randomized jump targets.'
VariantId: direct-and-indirect-syscalls-syswhispers-hell-s-gate-halo-s-gate
Command:
Invocation: "# Direct syscall via assembly:\nmov r10, rcx\nmov eax, <syscall_number> # e.g., 0x0026 for NtOpenProcess\nsyscall"
Context: 'Technique is embedded in malware/implant code. Effective against user-mode-only EDRs; ineffective against
kernel-level callback monitoring.'
Artifacts:
- 'ETW: Microsoft-Windows-Kernel-Process shows unusual syscall patterns'
- 'Call stack analysis: syscall return address not within ntdll.dll memory range'
- 'No single CLI command. Technique is embedded in malware code.'
ChokepointMapping: 'malware execution → direct syscall instructions bypass ntdll hooks → EDR userland visibility bypassed'
- Name: ETW Patching (EtwEventWrite)
FirstSeen: 2020-Q2
Status: Active
SourceURL: https://blog.xpnsec.com/hiding-your-dotnet-etw/
NotesShort: Patches EtwEventWrite with RET opcode to blind user-mode ETW
Notes: Patches EtwEventWrite or NtTraceEvent with a RET (0xC3) opcode to prevent user-mode ETW events from firing. Frequently
combined with AMSI bypass. Kernel-mode ETW Threat-Intelligence providers (ETW-TI) operate in ring-0 and are unaffected.
VariantId: etw-patching-etweventwrite
Command:
Invocation: "# Patches EtwEventWrite to return immediately:\n# VirtualProtect(EtwEventWrite, PAGE_EXECUTE_READWRITE)\n#
Write 0xC3 (RET) to first byte\n# VirtualProtect(EtwEventWrite, PAGE_EXECUTE_READ)"
Context: 'Used by CobaltStrike, Meterpreter, and custom loaders. Blinds ETW-based detections without killing any processes.'
Artifacts:
- 'ETW-TI: VirtualProtect call targeting EtwEventWrite address'
- 'Memory analysis: First byte of EtwEventWrite is 0xC3 (RET)'
- 'Absence of expected ETW events from a process that should be generating them'
ChokepointMapping: 'malware execution → VirtualProtect on EtwEventWrite → ETW event stream silenced'
- Name: AMSI Bypass (AmsiScanBuffer Patch)
FirstSeen: 2019-Q1
Status: Declining
SourceURL: https://www.cyberark.com/resources/threat-research-blog/amsi-bypass-patching-technique
NotesShort: Patches AmsiScanBuffer to return clean; largely mitigated by modern EDRs
Notes: Patches AmsiScanBuffer to return AMSI_RESULT_CLEAN, preventing script content scanning by PowerShell and other
AMSI-integrated hosts. Largely mitigated by modern EDRs via ETW Threat-Intelligence monitoring. Still attempted but
increasingly flagged.
VariantId: amsi-bypass-amsiscanbuffer-patch
Command:
Invocation: "[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true)"
Context: 'One-liner PowerShell AMSI bypass. Blinds script-based detection without disabling EDR. Increasingly
detected by memory protection monitoring.'
Artifacts:
- 'ETW-TI: VirtualProtect call targeting AmsiScanBuffer address'
- 'PowerShell ScriptBlock logging may capture the bypass attempt'
- 'Memory analysis: AmsiScanBuffer patched to return AMSI_RESULT_CLEAN'
ChokepointMapping: 'script execution → AmsiScanBuffer patched → script content scanning bypassed'
- Name: EDRSilencer
FirstSeen: 2024-Q2
Status: Active
SourceURL: https://github.com/netero1010/EDRSilencer
NotesShort: Blocks EDR network comms via WFP filters; EDR runs but cannot report
Notes: 'Blocks EDR network communication using Windows Filtering Platform (WFP) callout drivers to prevent telemetry and
alerts from reaching the management console. Does not kill EDR processes. Instead creates a silent EDR that cannot
report. Requires admin privileges.'
VariantId: edrsilencer
Command:
Invocation: "EDRSilencer.exe blockedr\n# Enumerates running EDR processes\n# Creates WFP filters blocking their
outbound network traffic\n# EDR continues running but telemetry never reaches console"
Context: 'Alternative to process termination. EDR stays alive but isolated from its management plane.'
Artifacts:
- 'Security EID 5441: WFP filter installation'
- 'Sysmon EID 1: EDRSilencer process execution'
- 'Network monitoring: EDR management traffic drops to zero'
- 'WFP filter audit: New persistent filters targeting security product executables'
ChokepointMapping: 'admin → WFP filters installed blocking EDR traffic (EID 5441) → EDR telemetry silenced'
- Name: Module Stomping / Reflective DLL Injection
FirstSeen: 2014-Q1
Status: Active
SourceURL: https://www.ired.team/offensive-security/code-injection-process-injection/modulestomping-dll-hollowing-shellcode-injection
NotesShort: Execute shellcode from trusted DLL address space; no disk artifacts
Notes: 'Module stomping overwrites a legitimately loaded DLL memory with shellcode, executing from within a trusted DLL
address space. Reflective DLL injection loads a DLL entirely from memory without the Windows loader. Both evade RWX
memory detections. Still used in Cobalt Strike and Havoc.'
VariantId: module-stomping-reflective-dll-injection
Command:
Invocation: "# Embedded in C2 frameworks. No standalone CLI.\n# 1. Load legitimate DLL (e.g., amsi.dll)\n# 2. Overwrite
.text section with shellcode\n# 3. Execute from legitimate DLL's address space"
Context: 'Technique is built into C2 frameworks (Cobalt Strike, Havoc). Leaves no disk artifact for the injected code.'
Artifacts:
- 'Sysmon EID 7: DLL loaded then memory region changed to RWX'
- 'ETW-TI: VirtualProtect calls on legitimate DLL memory regions'
- 'Memory analysis: DLL .text section hash mismatch with on-disk version'
ChokepointMapping: 'C2 execution → legitimate DLL memory overwritten with shellcode → code runs from trusted address space'
- Name: SafeMode Boot EDR Bypass
FirstSeen: 2019-Q4
Status: Active
SourceURL: https://www.sophos.com/en-us/blog/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/
NotesShort: Boot to Safe Mode where EDR services don't load; encrypt without interference
Notes: 'Boot Windows into Safe Mode where EDR services are not configured to load. Register ransomware as RunOnce startup
item, reboot into Safe Mode, encrypt without EDR running. Used by Snatch, REvil, BlackMatter, AvosLocker.'
VariantId: safemode-boot-edr-bypass
Command:
Invocation: "bcdedit /set {default} safeboot minimal\nreg add \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\"
/v \"payload\" /t REG_SZ /d \"C:\\temp\\ransomware.exe\" /f\nshutdown /r /f /t 0"
Context: 'Sets next boot to Safe Mode (minimal, no networking). Registers ransomware as RunOnce entry. Forces
immediate reboot. EDR services are not configured for Safe Mode boot.'
Artifacts:
- 'Sysmon EID 1: bcdedit.exe with /set and safeboot arguments'
- 'Sysmon EID 13: Registry modification to RunOnce key'
- 'Windows System EID 1074: System shutdown/restart initiated'
- 'Post-reboot: Ransomware process running with no EDR telemetry'
ChokepointMapping: 'admin → bcdedit sets Safe Mode boot → ransomware registered in RunOnce → reboot → EDR absent → encryption'
- Name: BlackSanta EDR Killer
FirstSeen: 2026-Q1
Status: Active
NotesShort: Russian-speaking actor targets HR departments; likely BYOVD or callback removal
Notes: Russian-speaking threat actor delivers BlackSanta EDR killer via social engineering targeting HR departments. Likely
uses BYOVD or kernel callback removal to disable EDR products.
VariantId: blacksanta-edr-killer
Prerequisites:
- Admin or SYSTEM privileges on target system (required without exception)
- Execution capability on target (process creation for bypass tool)
- For BYOVD: a vulnerable signed driver loadable via NtLoadDriver or SCM
- For kernel callback removal: ability to read/write kernel memory (via vulnerable driver)
- For user-mode techniques: VirtualProtect/NtProtectVirtualMemory access to target DLL memory
- Target EDR must be using one of the impaired mechanisms (user-mode hooks, ETW, kernel callbacks)
Chokepoints:
- Stage: Privilege Escalation
Input: Attacker has code execution on the target but lacks admin rights
Invariant: Must obtain admin or SYSTEM privileges. No BYOVD, callback removal, or PPL abuse works without elevation.
Observable: 'Sysmon EID 1 showing privilege escalation (token manipulation, UAC bypass, service exploitation) or process
running with high integrity level'
WhyCantBypass: Kernel drivers require admin to load. Process termination of protected processes requires SYSTEM. No EDR
bypass variant works from a standard user context.
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation with Token Elevation)
- Windows Security Event ID 4672 (Special Privilege Logon)
DetectionTier: Hunt
SigmaRef: sigma-rules/edr-bypass/hunt.yml
- Stage: EDR Telemetry Disruption
Input: Attacker has admin/SYSTEM privileges
Invariant: Must disrupt EDR telemetry collection. Options include loading a kernel driver (BYOVD), modifying
kernel memory (callback removal), patching userland hooks (ntdll unhooking, direct syscalls), patching ETW/AMSI functions,
blocking EDR network traffic (WFP filters), or booting into Safe Mode where EDR services don't load.
Observable: 'Kernel path: Sysmon EID 6 (Driver Loaded) for BYOVD variants. Userland path: Sysmon EID 7 (second ntdll.dll
loaded) or ETW-TI VirtualProtect on EtwEventWrite/AmsiScanBuffer. Network path: Security EID 5441 (WFP filter installed).
Safe Mode: Sysmon EID 1 showing bcdedit with safeboot argument.'
WhyCantBypass: EDR telemetry must be disrupted before the primary payload runs. Whether the attacker targets the kernel
(BYOVD, callbacks), userland (hooks, ETW, AMSI), network (WFP), or boot environment (Safe Mode), each path produces
observable artifacts specific to that mechanism.
LogSources:
- Sysmon Event ID 6 (Driver Loaded)
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4697 (Service Installed)
DetectionTier: Analyst
SigmaRef: sigma-rules/edr-bypass/analyst.yml
- Stage: Security Process Impairment
Input: Kernel protections are bypassed or disabled
Invariant: Must stop, kill, or blind the security agent process/service to prevent detection of the actual payload
Observable: 'Process termination of known EDR processes (MsMpEng.exe, CSFalconService.exe, SentinelAgent.exe). Service
state changes (sc stop, net stop). Sysmon EID 10 with PROCESS_TERMINATE access rights to security processes.'
WhyCantBypass: The EDR agent must be neutralized before the real payload runs. If the agent is still collecting telemetry,
the payload gets detected. The termination/impairment event is the artifact.
LogSources:
- Sysmon Event ID 10 (Process Access)
- Windows System Event ID 7036 (Service State Change)
- Sysmon Event ID 1 (sc.exe / net.exe invocation)
DetectionTier: Analyst
SigmaRef: sigma-rules/edr-bypass/analyst.yml
EvolutionTimeline:
- Date: 2012-2014
Event: Process hollowing, DLL injection, and reflective DLL loading established
Change: Foundational code injection primitives; reflective DLL loading (Stephen Fewer, 2014) enables in-memory DLL execution
without disk artifacts
DetectionImpact: User-mode behavioral hooks begin appearing; EDRs inject into ntdll.dll
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2017-2019
Event: Direct syscall techniques and SysWhispers published
Change: Attackers skip ntdll.dll entirely; Hell's Gate (2018) and SysWhispers (2019) make syscall bypasses accessible to
non-researchers; user-mode EDR hooks become defeatable without touching hooked memory
DetectionImpact: User-mode hook detection alone insufficient; kernel callbacks become critical
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2020-2021
Event: ntdll fresh-copy unhooking, ETW patching, and PPL abuse documented
Change: Unhooking removes all user-mode hooks in one operation; ETW patching blinds script content logging; PPL abuse (PPLdump)
enables termination of protected security processes; Heaven's Gate exploits WoW64 architecture
DetectionImpact: Kernel-level ETW-TI and process-callback monitoring become essential; user-mode telemetry no longer reliable
in isolation
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2022-Q1
Event: BYOVD operationalized by ransomware groups; EDRSandblast published
Change: BlackByte demonstrates BYOVD using RTCore64.sys in production ransomware; EDRSandblast (Wavestone) documents kernel
callback removal as a systematic technique; Terminator concept developed
DetectionImpact: Kernel driver load (Sysmon EID 6) becomes primary detection signal; known-bad driver hash lists required;
HVCI/Vulnerable Driver Blocklist adoption urged
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2023-Q1
Event: Terminator (Spyboy) sold commercially on RAMP forum
Change: BYOVD becomes a purchasable commodity ($300-$3,000); open-source clones proliferate; 23+ EDR/AV products targeted;
EDR killing is no longer only for sophisticated actors
DetectionImpact: Hash-based driver blocklists alone insufficient as variants proliferate; certificate-based and behavioral
detection required
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2024-Q3
Event: EDRKillShifter deployed by RansomHub; BYOVD adoption surges
Change: RansomHub deploys EDRKillShifter (Go-based, multi-driver loader) in August 2024; adopted by Play, Medusa, BianLian
within months; ~48% of high-severity 2024 ransomware attacks incorporate purpose-built EDR disablement (Cisco Talos);
EDRSilencer demonstrates network-layer EDR silencing
DetectionImpact: Driver load + security process termination correlation window becomes critical; single-driver-hash detection
obsolete against loaders; certificate age/trust detection gains importance
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2025-Q1
Event: Multiple ransomware groups ship purpose-built EDR killers bundled in primary payload
Change: DeadLock embeds novel Baidu driver-based loader; Reynolds integrates BYOVD directly into primary payload (first
observed Feb 2025); EDR killing transitions from a separate pre-ransomware step to a bundled capability
DetectionImpact: Dwell time between driver load and encryption shrinks; pre-encryption detection window narrows; driver
load + immediate bulk file activity correlation becomes highest-priority signal
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
Variants: []
EventType: event
- Date: 2026-Q1
Event: BlackSanta EDR killer discovered targeting HR departments
Change: New EDR killer variant delivered via HR-themed social engineering lures, attributed to Russian-speaking actor; specific
kill technique not yet fully detailed but targets EDR processes.
DetectionImpact: Existing BYOVD and kernel callback removal detections may catch underlying technique, but new tool signatures
and delivery via HR-themed lures require updated behavioral and email/endpoint rules.
TheConstant: Still requires admin/SYSTEM privileges on the target system to disable EDR, and must impair kernel callbacks,
user-mode hooks, or ETW. The core invariant prerequisites remain unchanged.
Variants: []
EventType: event
Detections:
- Level: Research
Description: Identify all kernel driver load events in the environment, focusing on non-Microsoft and recently signed drivers
LogSources:
- Sysmon Event ID 6 (Driver Loaded)
- Windows Security Event ID 4688 (Process Creation)
- Windows System Event ID 7045 (Service Installed)
Logic: 'Sysmon EID 6 driver loads where Signature is non-Microsoft, SignatureStatus is not Valid, the driver was signed within the last 90 days, or the hash matches the Microsoft Vulnerable Driver Blocklist.'
ExpectedFPRate: High
UseCase: Build baseline of all drivers loaded in the environment; identify gaps in driver allowlisting; compare against
Microsoft Vulnerable Driver Blocklist
SigmaRule: sigma-rules/edr-bypass/research.yml
- Level: Hunt
Description: Kernel driver load followed by security process termination or service stop
LogSources:
- Sysmon Event ID 6 (Driver Loaded)
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 10 (Process Access)
- Windows Security Event ID 4688 (Process Creation)
- Windows System Event ID 7036 (Service State Change)
Logic: 'Driver Loaded (EID 6) non-Microsoft OR signed <90 days OR hash on blocklist, AND within 5 minutes one of: EDR/AV process terminated (MsMpEng.exe, SophosFileScanner.exe, CSFalconService.exe, SentinelAgent.exe), OR sc.exe/net.exe stop targeting a security service, OR process access (EID 10) opening a security process with PROCESS_TERMINATE. Source must be an elevated process (high integrity or SYSTEM).'
ExpectedFPRate: Medium
UseCase: Proactive hunt for BYOVD-based EDR killing; correlates driver load with subsequent security tool impairment
SigmaRule: sigma-rules/edr-bypass/hunt.yml
- Level: Analyst
Description: Known vulnerable or recently signed driver load immediately followed by security process termination. Direct
EDR kill signal.
LogSources:
- Sysmon Event ID 6 (Driver Loaded)
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 10 (Process Access)
- Windows Security Event ID 4688 (Process Creation)
- Windows Security Event ID 4624 (Logon)
- Windows System Event ID 7036 (Service State Change)
Logic: 'Driver load (EID 6) where hash matches the Microsoft Vulnerable Driver Blocklist OR certificate was issued within 14 days by an unknown vendor, AND within 120 seconds a security process is terminated or service stopped (EID 7036) targeting MsMpEng.exe, SophosFileScanner.exe, CSFalconService.exe, SentinelAgent.exe, or CylanceSvc.exe. Source is SYSTEM or local Administrators, ideally after-hours or from a non-standard admin workstation.'
ExpectedFPRate: Low
UseCase: SOC alerting; direct escalation trigger for active EDR impairment; treat as ransomware precursor
SigmaRule: sigma-rules/edr-bypass/analyst.yml
Intel:
- Name: Wavestone - EDRSandblast
Tier: primary
URL: https://github.com/wavestone-cdt/EDRSandblast
Description: Open-source tool demonstrating kernel callback removal via vulnerable driver; includes 1000+ driver knowledge
base and detection of which EDR callbacks are registered; essential reference for defenders building callback-monitoring
detection
- Name: 'MITRE ATT&CK - T1562.001 Impair Defenses: Disable or Modify Tools'
Tier: primary
URL: https://attack.mitre.org/techniques/T1562/001/
Description: Primary technique definition covering BYOVD, process termination, and service stop as EDR impairment methods;
procedure examples link to known threat actor usage
- Name: 'MITRE ATT&CK - T1562.006 Impair Defenses: Indicator Blocking'
Tier: primary
URL: https://attack.mitre.org/techniques/T1562/006/
Description: Technique definition covering ETW patching, AMSI bypass, and other telemetry-blocking methods; distinct from
process termination; attacker keeps EDR running but blinds it
- Name: Microsoft - Vulnerable Driver Blocklist
Tier: primary
URL: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules
Description: The authoritative list of drivers known to be abused in BYOVD attacks; updated multiple times per year; use
as a hash and cert blocklist for Sysmon EID 6 detection rules
RelatedChokepoints:
- ransomware-service-manipulation
OsintSources:
- Platform: VirusTotal Intelligence
Query: tag:byovd positives:0
URL: https://www.virustotal.com/gui/search/tag%3Abyovd%20positives%3A0
Notes: Requires VT Intelligence subscription. Finds BYOVD samples with zero AV detections; these are the most dangerous current variants.
Pivot to the behavior tab to extract the specific driver filename, hash, and kernel callback manipulation sequence.
- Platform: GitHub Code Search
Query: '"PsSetCreateProcessNotifyRoutine" OR "ObRegisterCallbacks" path:*.c OR path:*.cpp'
URL: https://github.com/search?q=%22PsSetCreateProcessNotifyRoutine%22+OR+%22ObRegisterCallbacks%22&type=code
Notes: Finds kernel driver source code interacting with process notification callbacks, the primary mechanism BYOVD tools
manipulate. Monitor for new public tools targeting these APIs.
- Platform: GitHub Code Search
Query: '"EtwEventWrite" "0xC3" (path:*.c OR path:*.asm)'
URL: https://github.com/search?q=%22EtwEventWrite%22+%220xC3%22+%28path%3A*.c+OR+path%3A*.asm%29&type=code
Notes: Finds ETW patching implementations targeting EtwEventWrite with a RET opcode. New variants appear regularly; use
to track new ETW bypass techniques before they reach production campaigns.
- Platform: LOLDrivers
URL: https://www.loldrivers.io
Notes: 'Community-maintained catalog of known vulnerable (BYOVD) and malicious drivers with hashes, CVE references, and
detection guidance. Feed driver hashes from this list into Sysmon EID 6 detection rules and your EDR''s driver blocklist.
Updated regularly as new BYOVD tools emerge. Filter by ''Type: Vulnerable'' for BYOVD drivers; ''Type: Malicious'' for
purpose-built EDR killers like EDRKillShifter. Essential complement to Microsoft''s Vulnerable Driver Blocklist, which
lags behind community discovery.'
KnownBypasses:
- Bypass: Using a driver signed within days of use (defeats static hash blocklists)
Mitigation: Enable HVCI (Hypervisor-Protected Code Integrity) and enforce the Microsoft Vulnerable Driver Blocklist; require
EV code signing for all internal drivers
Detection: Alert on driver loads where certificate issuance date is within 14 days of the load event; combine with signer
reputation (first-time or unknown vendor)
- Bypass: Kernel callback removal instead of process termination (EDR stays running but callbacks are removed)
Mitigation: Implement anti-tamper monitoring that periodically verifies kernel callback registration from a protected process;
use VBS/HVCI to protect callback arrays
Detection: 'Detect absence of expected callbacks: if a known EDR driver is loaded but its registered callback count drops
to zero, treat as active compromise. Requires kernel-mode telemetry (e.g., custom minifilter or EDR with callback-integrity
monitoring).
'
- Bypass: EDRSilencer blocks EDR network communication via WFP instead of killing the process
Mitigation: Monitor WFP filter installation; require code signing for WFP callout drivers; implement out-of-band EDR health
checks from management console
Detection: Windows Security Event ID 5441 (WFP filter added); alert on WFP filter additions by non-Microsoft processes with
SYSTEM privileges outside maintenance windows.
- Bypass: User-mode unhooking (ntdll fresh copy) bypasses user-mode EDR hooks without kernel interaction
Mitigation: Implement kernel-level ETW Threat-Intelligence (ETW-TI) monitoring; ensure EDR uses kernel callbacks not just
user-mode hooks; enable Credential Guard
Detection: 'ETW-TI events fire on sensitive operations (NtReadVirtualMemory, NtWriteVirtualMemory, NtProtectVirtualMemory)
even when user-mode hooks are removed. Detect via Microsoft Defender ATP telemetry or kernel ETW providers; process-level
events for these APIs sourced from unusual parent chains are anomalous.
'
- Bypass: Indirect syscalls with call stack spoofing (legitimate-looking stack, no ntdll traversal)
Mitigation: EDR solutions must implement kernel callbacks rather than relying solely on user-mode hooks; enforce application
control to block unknown binaries
Detection: 'Kernel-level process and thread creation callbacks still fire regardless of syscall technique. Detect by correlating
process creation callbacks with the absence of expected user-mode telemetry. A process that creates threads but generates
no user-mode hook events is anomalous.
'
- Bypass: Living Off the Land using Windows-native tools (sc.exe, WMI) to stop security services instead of deploying a driver
Mitigation: Enable tamper protection on EDR products; use PPL to protect security processes from user-mode termination
Detection: See ransomware-service-manipulation chokepoint for sc.exe/net.exe service stop detection; combine with preceding
driver load context for full kill-chain coverage
YaraRules:
- yara-rules/edr-bypass-drivers.yar
RawLogs:
- Type: Sysmon
EventId: 6
Source: Microsoft-Windows-Sysmon/Operational
Description: Vulnerable/recently-signed kernel driver loaded. BYOVD technique initiation.
MatchedRules:
- Research
Sample: 'EventID: 6 (Driver Loaded)
UtcTime: 2024-08-22 03:44:11.774
ImageLoaded: C:\Windows\Temp\truesight.sys
Hashes: SHA256=3BE39706C4B3B49B8D5C49FEF3EFC2B748D6B3F8A1D0E9C2B4A6F8D0E2C4A6B8
Signed: true
Signature: Raynet Inc.
SignatureStatus: Valid
# Driver signed by "Raynet Inc.", a certificate issued 6 days prior to this event
# Hash matches Microsoft Vulnerable Driver Blocklist (truesight.sys / RogueKiller driver)
# Research rule: non-Microsoft driver OR recently-signed OR blocklist match
'
- Type: Sysmon
EventId: 10
Source: Microsoft-Windows-Sysmon/Operational
Description: BYOVD process opens handle to EDR process. Pre-kill access request.
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 10 (ProcessAccess)
UtcTime: 2024-08-22 03:44:12.891
SourceProcessGUID: {d4e5f6a7-4567-8901-defa-123456789012}
SourceProcessId: 2048
SourceImage: C:\Windows\Temp\killer.exe
TargetProcessGUID: {00000000-0000-0000-0000-000000000000}
TargetProcessId: 1876
TargetImage: C:\Program Files\Windows Defender\MsMpEng.exe
GrantedAccess: 0x1FFFFF
# PROCESS_ALL_ACCESS from non-trusted process to security process
# Follows driver load within 5 minutes. Hunt rule correlation.
'
- Type: Windows Event Log
EventId: 7036
Source: Service Control Manager
Description: Windows Defender service stopped after BYOVD driver loaded
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 7036 (The service entered the stopped state)
TimeCreated: 2024-08-22T03:44:13.4417820Z
Channel: System
param1: Windows Defender Antivirus Service
param2: stopped
# WinDefend stops within 120 seconds of driver load event
# Combined with EID 6 (driver) + EID 10 (process access) = full Analyst kill chain
'
- Type: Windows Event Log
EventId: 7040
Source: Service Control Manager
Description: Attacker disables WinDefend to prevent restart after stopping it
MatchedRules:
- Analyst
Sample: 'EventID: 7040 (The start type of the service was changed)
TimeCreated: 2024-08-22T03:44:13.6124330Z
Channel: System
param1: Windows Defender Antivirus Service
param2: disabled
# Service start type changed to "disabled" immediately after service stop
# Prevents restart via Task Scheduler or manual sc start
'
EmulationScript:
File: emulation/edr-bypass-techniques/emulate.ps1
Language: powershell
Description: Simulates EDR process handle opening, service stop/disable, and driver install event
SafetyNotes: 'Requires Administrator. Temporarily stops WinDefend for service stop telemetry (re-enables immediately). Does
NOT load vulnerable kernel drivers. Run in isolated lab VM only.
'
AtomicRef: T1562.001
TheConstant: Admin/SYSTEM privileges → bypass mechanism → security telemetry impaired
PreventionSummary: >
EDR bypass tools are themselves dual-use binaries that can be blocked before they reach the
security stack. Blocking vulnerable driver loads and known EDR-killer binaries at the policy
layer is the complementary control that EDR cannot provide for itself.
PreventionOpportunities:
- Category: Endpoint · Application Control
Control: Block known EDR-killer binaries by name, hash, and publisher signature
Impact: Prevents bypass tools from executing regardless of which EDR is being targeted;
does not rely on the security tool the attacker is trying to disable.
MagicSwordFit: MagicSword's built-in intelligence classifies and blocks EDR-killer binaries
as they are identified, including EDRKillShifter, PCHunter, and ProcessHacker variants
used as LOLBAS in bypass chains.
MagicSwordTag: edr-killers
- Category: Endpoint · Application Control
Control: Enforce HVCI and Microsoft's Vulnerable Driver Blocklist to block BYOVD attacks
Impact: Removes the kernel escalation path that the majority of BYOVD-based EDR killers
depend on; no vulnerable driver = no kernel-level bypass.
MagicSwordFit: MagicSword tracks vulnerable driver publishers and can block driver loads
from untrusted or revoked signers before they reach the kernel.
MagicSwordTag: byovd
- Category: Endpoint
Control: Deploy Windows Credential Guard and Virtualization-Based Security (VBS)
Impact: Reduces the kernel attack surface available to BYOVD techniques without requiring
per-driver blocklist maintenance; hardens the platform beneath the EDR stack.