Skip to content

Hide Navigation Hide TOC

Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze (387df17d-3b04-448f-8669-9e7fd5e5fd8c)

Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.

Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze (387df17d-3b04-448f-8669-9e7fd5e5fd8c) Sigma-Rules Disable or Modify Tools - T1562.001 (ac08589e-ee59-4935-8667-d845e38fe579) Attack Pattern 1
Impair Defenses - T1562 (3d333250-30e4-4a82-9edc-756c68afc529) Attack Pattern Disable or Modify Tools - T1562.001 (ac08589e-ee59-4935-8667-d845e38fe579) Attack Pattern 2