Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze

Rule Info

Name
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.
Date
2025-11-27 00:00:00
Modified
None
Id
387df17d-3b04-448f-8669-9e7fd5e5fd8c
Tags
attack.defense-impairment attack.t1685
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #5966 from @nasbench - Update mitre tags to use attack v19
2026-04-29
Swachchhanda Shrawan Poudel
Merge PR #5777 from @swachchhanda000 - feat: more edrfreeze rules
2025-12-10