---
title: "Threat Actor Defense Evasion: How Attackers Disable AV & EDR"
url: https://daily.dev/posts/threat-actor-defense-evasion-how-attackers-disable-av-edr-jgvbyowfr
source_url: https://www.huntress.com/blog/how-attackers-disable-av-edr
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:52.730Z
updated: 2026-05-31T08:09:01.278Z
tags: ["security"]
reading_time: 7
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat Actor Defense Evasion: How Attackers Disable AV & EDR

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 7 min read · 0 upvotes · 0 comments

## Summary

Threat actors are increasingly targeting endpoint security tools themselves rather than just evading them. Common techniques include blocking EDR communications via malicious Windows Firewall rules (using tools like EDRSilencer), uninstalling agents after privilege escalation, and Bring Your Own Vulnerable Driver (BYOVD) attacks that exploit signed but vulnerable drivers to gain kernel-mode access and terminate security processes. Real-world 2026 examples include an EnCase forensic driver exploit that killed 59 security processes and a malvertising campaign using a vulnerable Huawei audio driver. Huntress counters these with real-time BYOVD detection, firewall rule abuse detection and remediation, and Tamper Protection that prevents agents from being stopped or uninstalled.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/how-attackers-disable-av-edr>

## Similar posts on daily.dev

- [Threat actor adds advanced ‘EDR killer’ tools to ransomware-as-a-service platform](https://daily.dev/posts/threat-actor-adds-advanced-edr-killer-tools-to-ransomware-as-a-service-platform-vgthonbtl) · CSO Online · 0 upvotes · 0 comments
- [How the GodDamn Ransomware Driver Bypasses Your EDR](https://daily.dev/posts/how-the-goddamn-ransomware-driver-bypasses-your-edr-6ruyzz7fu) · Latest Hacking News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/threat-actor-defense-evasion-how-attackers-disable-av-edr-jgvbyowfr)
