Rule Info
Name
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques.
This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.
Date
2025-11-27 00:00:00
Modified
None
Id
387df17d-3b04-448f-8669-9e7fd5e5fd8c
Tags
attack.defense-impairment attack.t1685
Type
Community Rule
Link to Public Repo
