Silencing the EDR Silencers

Silencing the EDR Silencers

The article shows how attackers silence EDRs with firewall/WFP rules that block cloud communication, and how defenders can prevent or rapidly remove those rules via registry callbacks and APIs.