Skip to content

Hide Navigation Hide TOC

Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze (387df17d-3b04-448f-8669-9e7fd5e5fd8c)

Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.

Cluster A Galaxy A Cluster B Galaxy B Level
Disable or Modify Tools - T1685 (bbde9781-60aa-4b8a-a911-895b0c1b3872) Attack Pattern Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze (387df17d-3b04-448f-8669-9e7fd5e5fd8c) Sigma-Rules 1