SilentButDeadly Blocks EDR on Windows Without Detection

17 Nov 2025

SilentButDeadly is a network communication blocker that impairs security measures on Windows systems without using kernel-level techniques. The technique focuses on exploiting the Windows Filtering Platform (WFP) to disrupt EDR and antivirus connectivity discreetly.

Mechanism and Methodology

This tool operates by verifying administrator privileges, then identifying and targeting EDR processes such as SentinelAgent.exe and MsMpEng.exe. It quickly establishes high-priority WFP sessions, installing bidirectional filters per targeted process. The result is a halt in outbound telemetry and inbound communications for cloud updates and threat intelligence.

  • Administrator privileges are essential for the tool's execution.
  • SilentButDeadly uses dynamic sessions, leaving fewer forensic traces.
  • It attempts to disable associated EDR services to stop system restarts and updates.

Detection and Mitigation Strategies

For detecting SilentButDeadly, system administrators can monitor Windows event logs for specific WFP-related events, notably Event IDs 5441, 5157, and 5152. Effective mitigating methods involve real-time WFP monitoring and ensuring redundant communication channels for telemetry. Protection of EDR services through kernel-level drivers or Windows protected processes is crucial. While dynamic, the technique is rendered ineffective against EDR solutions protected by kernel-level network drivers.

Impact and Considerations

This new evasion method underscores vulnerabilities within Windows security mechanisms that are exploitable through legitimate features like WFP. Administrators must bolster their monitoring capabilities and enhance the protection strategies for EDR and antivirus tools to prevent such disruptions.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6528181
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1328880
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
516820
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
456117
downloads

News and reviews for Desktop Windows

XDefiant's Origins Linked to Splinter Cell Project

XDefiant began as a Splinter Cell project at Ubisoft in 2017, before pivoting in 2024. Developers moved on to AdHoc Studio.

Read more

RONINGLOADER Exploits in Campaign Targeting Chinese Users

RONINGLOADER used by Dragon Breath for Gh0st RAT attacks on Chinese users, bypassing defenses.

Read more

Windows 11 Fixes Shut Down Bug with Update KB5067036

Microsoft's Windows 11 update KB5067036 fixes the 'Update and shutdown' bug. Rolling out in October 2025, it enhances shutdown reliability.

Read more

Cold Fear Delisted from Steam, Possible Remaster Ahead

Cold Fear, the 2005 horror game by Darkworks, disappears from Steam. Atari might remaster it soon.

Read more

SilentButDeadly Blocks EDR on Windows Without Detection

SilentButDeadly disrupts security communications on Windows via the Filtering Platform, affecting EDR and antivirus tools.

Read more

Discover Unique New Steam Games Released in November

Explore five intriguing new Steam games launched in November 2025, featuring innovative narratives and gameplay mechanics.

Read more

Madness Returns Enhanced with Fan Patch on PC

Modder Wemino releases a fan patch for Madness Returns, enhancing PC performance. Users enjoy improved gameplay and visuals.

Read more

Eleventh Hour Games to Self-Publish Last Epoch

Skystone and Eleventh Hour Games nearly collaborated on Last Epoch. Krafton's backing raises new growth prospects.

Read more

New Indie Game Offers Poker-Themed Idle Experience

Mash releases This Ain't Even Poker, Ya Joker, blending poker with idle mechanics. Demo available on Steam now.

Read more

TikTok Scam Deploys Malware via Fake Guides

Cybercriminals use TikTok to circulate malware through fake activation guides, targeting unwary users. Vigilance against TikTok scams is crucial.

Read more