Threat actors are increasingly targeting endpoint security tools themselves rather than just evading them. Common techniques include blocking EDR communications via malicious Windows Firewall rules (using tools like EDRSilencer), uninstalling agents after privilege escalation, and Bring Your Own Vulnerable Driver (BYOVD) attacks that exploit signed but vulnerable drivers to gain kernel-mode access and terminate security processes. Real-world 2026 examples include an EnCase forensic driver exploit that killed 59 security processes and a malvertising campaign using a vulnerable Huawei audio driver. Huntress counters these with real-time BYOVD detection, firewall rule abuse detection and remediation, and Tamper Protection that prevents agents from being stopped or uninstalled.

7m read timeFrom huntress.com
Post cover image
Table of contents
Attacker tradecraft and tools: How they’re wrecking antivirus and EDRReal-world examplesWhat Huntress does to protect the hunters on the endpointWant to learn more?
1 Impression