LoFP LoFP / legitimate windows error reporting operations

Techniques

Sample rules

Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze

Description

Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.

Detection logic

condition: selection
selection:
  CallTrace|contains:
  - \dbgcore.dll
  - \dbghelp.dll
  SourceImage|endswith: \WerFaultSecure.exe
  TargetImage|endswith: \MsMpEng.exe