CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Threat Actor Defense Evasion: How Attackers Disable AV & EDR

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 687

As cited

Copy frozen at (site build).

threat intel

Threat Actor Defense Evasion: How Attackers Disable AV & EDR

Threat actors employ various techniques to disable antivirus and endpoint detection and response (EDR) solutions, including exploiting vulnerable drivers, tampering with security configurations, and modifying firewall rules. These evasion tactics allow attackers to operate undetected on compromised systems. Understanding these methods is critical for defensive teams to maintain visibility and protect their environments.

Why it matters: Security operations and incident response teams need to detect and prevent AV/EDR disablement attacks, as successful evasion directly undermines visibility into endpoint compromise and enables attackers to operate freely.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary