EDR-Freeze Technique Exploits Windows Error Reporting

24 Sep 2025

Endpoint detection and response (EDR) systems are critical in protecting against ransomware and other cybersecurity threats. However, a new technique called EDR-Freeze presents a sophisticated method to evade such defenses. This technique leverages Windows Error Reporting and the MiniDumpWriteDump function to temporarily suspend antivirus processes, thereby bypassing their protective measures.

Ingenious Use of Windows Error Reporting

The novelty of EDR-Freeze lies in its ability to operate without installing vulnerable drivers, a common requirement in previous evasion tactics. By utilizing the MiniDumpWriteDump function, it manages to create a minidump of target processes by suspending their threads during the operation. This is particularly significant as it circumvents the typical vulnerabilities exploited with kernel drivers.

The technique, however, faces two primary challenges: extending the brief execution time typical of MiniDumpWriteDump and handling antivirus processes fortified by Protected Process Light (PPL). The researcher overcame these challenges by reverse-engineering WerFaultSecure. This allowed them to trigger MiniDumpWriteDump effectively for any target process.

Overcoming PPL Challenges with CreateProcessAsPPL

The research demonstrated that when combined with CreateProcessAsPPL, WerFaultSecure is capable of launching and suspending PPL-protected child processes—a vital step in this evasion process. The technique exploits a race condition, orchestrating a sequence of actions that start with running WerFaultSecure as a PPL process and setting parameters to dump the target.

Once the target is suspended, WerFaultSecure itself is suspended using PROCESS_SUSPEND_RESUME and NtSuspendProcess functions. If both are suspended simultaneously, the antivirus or EDR process remains indefinitely frozen. This clever pause extends the time the target defense system is inactive, allowing for potentially malicious activities to proceed unchecked without the need to use kernel drivers.

Impact on Cybersecurity Practices

This new method addresses several shortcomings of the BYOVD (Bring Your Own Vulnerable Driver) approach by eliminating driver installation. It provides a flexible approach to controlling when security processes operate or are suspended, offering an unprecedented level of stealth and control for threat actors.

Details of this method, including a proof-of-concept, have been shared publicly on GitHub, increasing awareness and understanding of how these evasive maneuvers can be performed. A mitigating response has been shared in the form of a KQL detection query, but it underscores the continual arms race between those developing cybersecurity defenses and those seeking to overcome them.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
5868926
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1068099
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
443821
downloads
Geometry Dash

Geometry Dash

Latest update Geometry Dash download for free for Windows PC or Android mobile

4
539 reviews
381645
downloads

News and reviews for Desktop Windows

PCGaming Features Over 30 New Titles at Tokyo Event

PCGaming hosts its Tokyo Direct event, showcasing over 30 games from top publishers, including exclusive interviews and trailers. The virtual showcase will stream on PC Gamer's platforms at the Tokyo Game Show.

Read more

EDR-Freeze Technique Exploits Windows Error Reporting

EDR-Freeze uses Windows Error Reporting and MiniDumpWriteDump to suspend antivirus processes without vulnerable drivers.

Read more

Dune Awakening Joins Fanatical's $5 Mystery Game Bundle

Fanatical unveils its latest Mystery Bundle, featuring Dune Awakening for under $5. This bundle offers a mix of survival and online action games with small base building elements. The offer, including other titles like Hell is Us, is time-limited and could sell out quickly.

Read more

Bladesong Offers Unique Swordcrafting Experience

Bladesong introduces a new demo on Steam, focusing on the artistry of swordcrafting through a captivating story mode and an open Creative Mode.

Read more

Darktide Update Brings Fresh Content to Enthusiastic Players

Darktide's latest update, Bound by Duty, unveils new enemies, weapons, maps, and a dynamic event, enhancing player engagement. This marks a considerable iteration in Warhammer 40k's gaming experience.

Read more

Seleen UI Offers Sleek Overhaul for Windows 11

Seleen UI transforms the Windows 11 desktop with a customizable skin that includes various system controls and resource pack options for enhanced personalization.

Read more

Intel Aims to Compete with Nvidia Using XeSS Multi-Frame Generation

Intel explores multi-frame generation in its XeSS tech, challenging Nvidia. Driver files hint at AI-driven enhancements for Arc GPUs, but official confirmation awaits.

Read more

Chrono Odyssey Developers Address Community Feedback

Chrono Odyssey developers share an update on game improvements and community engagement following player feedback from a recent playtest earlier this year.

Read more

Valor Mortis: A New Tactical Combat Adventure Unveiled

One More Level launches Valor Mortis, a Dark Souls-inspired game combining strategic combat with fast-paced platforming. A public playtest begins October 6, offering early access to its immersive world and unique gameplay as players uncover secrets on their journey.

Read more

Microsoft Addresses Windows 11 Facial Recognition Bug

Microsoft's latest Windows 11 update resolves facial recognition issues, enabling devices to receive version 24H2. Learn more about remaining challenges and the forthcoming 25H2 update.

Read more