mirror of
https://github.com/senzee1984/EDRPrison
synced 2026-08-09 13:09:24 +00:00
Update README.md
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
# EDRPrison
|
||||
EDRPrison leverages a legitimate WFP callout driver to silence EDR. Inspired by [Shutter](https://github.com/dsnezhkov/shutter), [FireBlock](https://www.mdsec.co.uk/2023/09/nighthawk-0-2-6-three-wise-monkeys/), and [EDRSilencer](https://github.com/netero1010/EDRSilencer), I have researched evasion based on network intervention. Different from them, EDRPrison installs and loads an external legitimate WFP callout driver rather than relying on the built-in WFP. Additionally, EDRPrison blocks EDR processes' outbound traffic by dynamically adding run-time filters without directly interacting with them and their executables.
|
||||
EDRPrison leverages a legitimate WFP callout driver [WinDivert](https://reqrypt.org/windivert.html) to silence EDR. Inspired by [Shutter](https://github.com/dsnezhkov/shutter), [FireBlock](https://www.mdsec.co.uk/2023/09/nighthawk-0-2-6-three-wise-monkeys/), and [EDRSilencer](https://github.com/netero1010/EDRSilencer), I have researched evasion based on network intervention. Different from them, EDRPrison installs and loads an external legitimate WFP callout driver rather than relying on the built-in WFP. Additionally, EDRPrison blocks EDR processes' outbound traffic by dynamically adding run-time filters without directly interacting with them and their executables.
|
||||
|
||||
In summary, EDRPrison has the following features and capabilities
|
||||
- Utilize a legitimate WFP callout driver to extend capabilities while being benign
|
||||
|
||||
Reference in New Issue
Block a user