📣 Send us your press release
Site updates every 15 minutes
Technology

Picus Security Identifies New EDR-Freeze Attack Technique

Cybersecurity firm Picus Security has identified a new attack method dubbed "EDR-Freeze" that can neutralize endpoint security software without triggering alerts. The attack effectively suspends security processes, creating a blind spot for malicious activity.

30 September 2026

Picus Security has revealed a new threat to endpoint security, termed "EDR-Freeze," which allows attackers to disable security software without detection. Unlike traditional methods that aim to crash or terminate security programs, EDR-Freeze suspends their operations, rendering them inactive but technically running.

The attack leverages legitimate Windows components, specifically the MiniDumpWriteDump function and the WerFaultSecure.exe tool. WerFaultSecure.exe, part of the Windows Error Reporting service, is used to create memory dumps of processes for debugging. EDR-Freeze exploits this by instructing WerFaultSecure.exe to initiate a memory dump of the target EDR process. The MiniDumpWriteDump function, as part of its design, suspends all threads within the target process to ensure a consistent dump. The attacker then uses the NtSuspendProcess function to immediately suspend WerFaultSecure.exe itself, creating a deadlock where the EDR remains suspended indefinitely.

This technique operates entirely in user mode, meaning it does not require elevated privileges or exploitation of kernel-level vulnerabilities. This makes it particularly dangerous as it bypasses many security controls designed to protect against lower-level system manipulation. The resulting "frozen" EDR creates a critical blind spot, enabling attackers to conduct further malicious activities such as deploying ransomware, exfiltrating data, or executing other commands undetected.

Picus Security offers the capability to simulate EDR-Freeze attacks and numerous other threats through its platform. This allows organizations to validate their security defenses against emerging techniques and proactively improve their security posture. The EDR-Freeze threat is available for simulation within the Picus Threat Library.

Original source: picussecurity.com