EDRSilencer

by netero1010 · 未分类 · ★ 1.8k

About EDRSilencer

EDRSilencer Inspired by the closed source FireBlock tool FireBlock from MdSec NightHawk, I decided to create my own version and this tool was created with the aim of blocking the outbound traffic of running EDR processes using Windows Filtering Platform (WFP) APIs. This tool offers the following features: Search known running EDR processes and add WFP filter to block its outbound traffic Add WFP filter for a specific process Remove all WFP filters created by this tool Remove a specific WFP filter by filter id Support to run in C2 with in-memory PE execution module (e.g., ) Some EDR controls...

Quick Facts

Stars1,825
Forks237
LanguageC
Category未分类
LicenseMIT
Quality Score30.75/100
Open Issues8
Last Updated2024-11-03
Created2023-12-26
Est. Tokens~11k

More 未分类 Tools

Explore other popular 未分类 tools:

View all 未分类 tools →

Popular C Agent Tools

Frequently Asked Questions

What is EDRSilencer?

EDRSilencer is A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.. It is categorized as a 未分类 with 1.8k GitHub stars.

What programming language is EDRSilencer written in?

EDRSilencer is primarily written in C.

How do I install or use EDRSilencer?

You can find installation instructions and usage details in the EDRSilencer GitHub repository at github.com/netero1010/EDRSilencer. The project has 1.8k stars and 237 forks, indicating an active community.

What license does EDRSilencer use?

EDRSilencer is released under the MIT license, making it free to use and modify according to the license terms.

View on GitHub → Browse 未分类 tools