EDR-Freeze Suspends Antivirus Using Native Tools

23 Sep 2025

A breakthrough in security research has emerged with the introduction of EDR-Freeze, a method devised to temporarily disable antivirus processes and Endpoint Detection and Response (EDR) agents on Windows systems. Crafted by a Zero Salarium specialist, this method employs built-in system utilities, eschewing the need for vulnerable third-party drivers, which often pose security risks.

Exploiting System Tools and Race Conditions

The EDR-Freeze method cleverly leverages native operating system behavior alongside race conditions. One core component of the exploit is MiniDumpWriteDump, a function that suspends all threads of a target process while generating a snapshot. Typically, the initiator of the dump is responsible for resuming the process once the dump is complete. However, EDR-Freeze subverts this workflow, leaving the process suspended.

A critical aspect of this technique is manipulating WerFaultSecure to execute with Protected Process Light (PPL) privileges at the WinTCB level, enabling it to initiate a dump of a specified Process ID (PID). During this operation, WerFaultSecure unexpectedly suspends itself at a crucial juncture. This self-suspension means the affected process cannot resume, as the initiator tasked with its revival is no longer operational.

Utility Details and Demonstration

The EDR-Freeze utility itself is relatively straightforward, requiring only a target PID and a defined pause time in milliseconds. By systematically executing the outlined steps, the utility effectively keeps the antivirus process immobilized. Its efficacy was demonstrated by suspending MsMpEng.exe, a core component of Windows Defender, on a Windows 11 24H2 system. Process Explorer was used to monitor the suspension status, showcasing the potential real-world implications of the technique.

Security Implications and Recommendations

This innovative approach represents a significant concern for endpoint security frameworks, as EDR-Freeze operates entirely within user mode, bypassing conventional security measures reliant on detecting third-party driver exploitation. The essence of the risk lies in the method's ability to manipulate trusted system components to achieve its goals.

To counteract these vulnerabilities, the research alludes to the necessity of vigilant monitoring of WerFaultSecure's boot parameters. Observing for any anomalies that could indicate unsanctioned references to PIDs of sensitive services, such as LSASS, antivirus processes, or EDR agents, is critical. Implementing comprehensive measures to verify the integrity of protected-process boot chains and detect unusual dump-creation patterns is essential for bolstering defenses against potential misuse.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6743198
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1430107
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
577619
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
463517
downloads

News and reviews for Desktop Windows

Destiny 2's Renegades Expansion Boosts Player Count on Steam

Destiny 2's Renegades expansion led to a player spike on Steam. Despite Star Wars themes, numbers remain below past peaks.

Read more

Microsoft Fixes LNK Vulnerability Exploited Since 2017

Microsoft patched the long-standing LNK security flaw in Windows as part of the November 2025 update, impacting user security.

Read more

Highlights from PC Gaming Show: Most Wanted 2025 Countdown

PC Gaming Show: Most Wanted 2025 on December 4 reveals top PC games with new trailers and announcements. Anticipated by gamers and industry experts.

Read more

Microsoft Alters LNK File Behavior to Tackle Vulnerability

Microsoft changes LNK file handling in response to exploited vulnerability CVE-2025-9491, affecting multiple cybercrime groups.

Read more

Norsca Rework Highlights Tides of Torment Expansion

Tides of Torment expansion releases 2023-12-04, with Norsca rework featuring new units and mechanics for Sayl the Faithless.

Read more

Microsoft Ad Promotes Copilot, Sparks Mixed Reactions

Microsoft released a Windows 11 ad featuring Copilot, aiming to showcase advanced voice integration. The ad has sparked mixed reactions, potentially inflating expectations.

Read more

Windows Accessibility Upgrades Enhance User Experience

Windows enhances accessibility with new voice and dictation features, benefiting diverse user needs in 2025.

Read more

Helldivers 2 Trims PC Install Size by 85%

Helldivers 2's PC install size reduced to 23 GB from 154 GB, thanks to deduplication efforts by Arrowhead Game Studios and Nixxes Software.

Read more

PCGamingShow to Reveal Top 25 PC Games by 2025

PC Gamer hosts PCGamingShow: Most Wanted on 2025-12-04, unveiling top PC games. Streaming globally, includes exciting game trailers and announcements.

Read more

Windows Concept Imagines 'Liquid Glass' Redesign

YouTube creator unveils Liquid Glass design, reshaping Windows with modern features that fans want Microsoft to consider.

Read more