EDR-Redir V2 Bypasses Windows Defender with Redirection Loops

02 Nov 2025

EDR-Redir V2 introduces a new method of evading Windows Defender on Windows 11 by leveraging fake program files and redirection loops.

Mechanism Exploited

The tool exploits Windows bind link technology to manipulate EDR systems. It targets parent directories of EDR installations, such as Program Files, creating redirection loops via subfolder mirroring. This method avoids disruptions to legitimate applications.

Earlier EDR-Redir versions had limitations due to protective blocking of direct folder redirections. Version 2 overcomes this by looping subfolders while isolating specific EDR paths for manipulation without needing kernel privileges.

Demonstration Details

Researcher TwoSevenOneT demonstrated EDR-Redir V2 on Windows 11, targeting Windows Defender’s subfolder at C:\ProgramData\Microsoft\Windows Defender. By executing the tool with specific parameters, the researcher confirmed successful operation via console results.

The technique reroutes Defender's access attempts through the TEMPDIR, effectively hiding original files and enabling potential malicious code loading. An accompanying video and tool are shared on GitHub and YouTube for public insight.

Security Implications

This approach reveals vulnerabilities in EDR systems' folder-specific safeguards, suggesting room for improvement. The technique’s simplicity poses a risk to enterprise environments if unaddressed. To counteract, defenders should monitor bind link usage and strengthen integrity checks on EDR paths. EDR vendors might need to enhance their protections without compromising application usability.

Research updates by TwoSevenOneT are available on X, providing insights for pentesting applications.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6333472
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1248847
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
491787
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452871
downloads

News and reviews for Desktop Windows

Thief VR Set for December Release with Promising Features

Thief VR: Legacy of Shadow, launching 2025-12-04, introduces new protagonist Magpie with immersive gameplay changes.

Read more

EDR-Redir V2 Bypasses Windows Defender with Redirection Loops

EDR-Redir V2 uses fake program files to evade Windows Defender on Windows 11, exploiting directory redirection tactics.

Read more

Office 2021 Lifetime License Discounted to $39.97

For a limited time, purchase Office 2021 for $39.97, a significant discount from its usual $219.99 price.

Read more

Spooky Express Update Brings Over 200 New Levels

Spooky Express, by Draknek and Friends, expands Cosmic Express with 200+ levels, now on Steam.

Read more

Skinballs Preserved by Strong Museum for Future Study

The Strong Museum has preserved Skinballs, a Saints Row test NPC, for future study and preservation, enhancing gaming history.

Read more

Cubic Odyssey Offers 40% Off With New Features

Cubic Odyssey, by Atypical Games, blends survival, crafting, and space travel. Available on Steam with a 40% discount until 2023-11-14.

Read more

Fractured Utopias Adds Depth to Frostpunk 2 Factions

Fractured Utopias enriches Frostpunk 2 with new skill trees and events, launching on 2025-12-08. Early testing open until 2025-11-03.

Read more

War Sails Launches Naval Combat in Bannerlord

War Sails in Bannerlord ushers in naval tactics with an expansion available from 2023-11-26, priced at $24.99.

Read more

AMD Confirms Continued Windows 10 Driver Support

AMD assures users that Windows 10 drivers remain supported with the new Adrenalin Edition 25.10.2 release.

Read more

Timberborn Nears 1.0 Release with Expanded Features

Timberborn is approaching its 1.0 release with new maps and mechanics; testing of new features is ongoing.

Read more