Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Silent Threat: Red Team Tool EDRSilencer Disrupting Endpoint Security Solutions
Trend AI Research Blog Oct 2024

Silent Threat: Red Team Tool EDRSilencer Disrupting Endpoint Security Solutions

Red Team ToolsEDR EvasionWFP

EDRSilencer was originally developed as a red team tool, but this article documents the first observed cases of it being weaponized by real threat actors in the wild. The tool abuses the Windows Filtering Platform (WFP) — a legitimate Windows networking framework — to silently block EDR telemetry from reaching its cloud console. By inserting WFP filters, attackers effectively blind security teams without triggering alerts or crashing the EDR process. This research covers the technical mechanism, affected EDR products, detection strategies using ETW and kernel callbacks, and mitigation approaches. The article gained significant industry attention and was widely cited.