Techniques
Sample rules
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
- source: sigma
- technicques:
- t1562
- t1562.001
Description
Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.
Detection logic
condition: selection
selection:
CallTrace|contains:
- \dbgcore.dll
- \dbghelp.dll
SourceImage|endswith: \WerFaultSecure.exe
TargetImage|endswith: \MsMpEng.exe