// soc investigation 2026-06-21
SOC344 EDR Tampering Attempt via EDR-Freeze
letsdefend High ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1562-001
analyst verdict TRUE POSITIVE
✓

SOC344 - EDR Tampering Attempt via EDR-Freeze

Severity: High | Hostname: WS-Prod-02 | IP: 172.16.20.69 | Date: Sep 26, 2025

Summary

A brute-force RDP campaign against WS-Prod-02 originated from 212.8.243.56, a VPN exit node geolocated in the Netherlands and flagged malicious on AbuseIPDB. The attacker initially attempted to authenticate as admin, but ultimately achieved a successful logon as letsdefendsuc at Sep 26, 2025 01:00 PM.

Following the successful logon, the attacker downloaded and executed EDR-Freeze_1.0.exe (PID 1684) from the Downloads folder. EDR-Freeze is a publicly released proof-of-concept tool that abuses legitimate Windows components to put EDR or antivirus processes into an indefinite suspended (“coma”) state — without crashing or terminating them, and without requiring a vulnerable kernel driver (BYOVD).

How EDR-Freeze Works

  1. The tool spawns WerFaultSecure.exe at WinTCB Protected Process Light (PPL) level, which grants it authority to interact with other PPL-protected processes such as EDR agents.
  2. It instructs WerFaultSecure.exe to call MiniDumpWriteDump against the target EDR/AV PID — a legitimate API used to capture memory dumps, which suspends all threads in the target as a side effect of ensuring dump consistency.
  3. A monitor thread in EDR-Freeze polls the target process until it confirms the suspension has taken effect.
  4. At that exact moment, EDR-Freeze suspends WerFaultSecure.exe itself using NtSuspendProcess.
  5. This creates a deadlock: the target EDR process will only resume once WerFaultSecure.exe completes its dump, but WerFaultSecure.exe is now also suspended and can never finish. The EDR remains frozen indefinitely, with its process still visible but no active monitoring.

The observed command line confirms this technique precisely:

WerFaultSecure.exe /h /pid 6080 /tid 6076 /encfile 236 /cancel 300 /type 268310

The combination of /encfile, /cancel, and /type 268310 alongside /pid and /h is the highest-fidelity indicator published for this technique — generic WerFaultSecure crash invocations don’t carry this parameter set together.

MITRE ATT&CK

TacticTechniqueID
Credential AccessBrute Force: Password GuessingT1110.001
Defense EvasionValid AccountsT1078
Defense EvasionImpair Defenses (platform tag)T1562.001

Analyst note: T1562.001 was selected as the closest available platform tag. EDR-Freeze does not actually disable or modify the EDR binary — it exploits a race condition in legitimate Windows dump tooling to force a suspension deadlock. As of this case date, MITRE has no sub-technique that precisely captures suspension-based “coma state” attacks; this is worth flagging in any future write-up as the technique becomes more prevalent.

Indicators of Compromise

TypeValue
Malicious IP212.8.243[.]56 (NL, VPN exit node)
Compromised accountletsdefendsuc
Malicious fileC:\Users\LetsDefend\Downloads\EDR-Freeze_1.0.exe
SHA256970c7834e58b6ef22473875167a333dbb33bf7b667d1cb814829f68579cd85f7
EDR-Freeze processPID 1684
Targeted PID (via WerFaultSecure)6080

Analysis Reports

🔍 VirusTotal — SHA256 — confirmed malicious, identified as EDR-Freeze hacking tool
🔍 VirusTotal — IP — 212.8.243.56 reputation check
🌐 AbuseIPDB — IP — 212.8.243.56 flagged malicious, VPN exit node, Netherlands

Response Actions