Your EDR is running. Detecting everything. Alerting on nothing.
EDRSilencer blocks all EDR outbound traffic using Windows Filtering Platform. The agent keeps running. Detections keep firing. Nothing reaches the cloud. No alerts. No telemetry. Blind.
Works against Defender, SentinelOne, CrowdStrike, Cortex XDR, Carbon Black, Elastic, Trellix, FortiEDR, ESET, TrendMicro, and more.
Additional techniques covered: WFP filters, hosts file manipulation, NRPT rules, null sinkholing, firewall rules.
If your SOC relies on cloud-based alerting and you are not monitoring for WFP filter creation, you have a problem.
https://t.co/9y586rIknx
https://t.co/egLu98X3bC
Authors: @ipurple
#DefenseEvasion #ThreatIntel #InfoSec
Th vast majority of CISOs do not work at Google-sized companies, and will not have to worry about 0days
There’s a disconnect between the Mythos discourse, and what actually happens at most orgs:
Still can’t identify assets and IPs, biggest threat is still phishing, lack of defined ID mgmt and access controls, shadow IT, misconfig’d S3 buckets…
If you work at one of those companies (applies to most people) you have a LOT of work to do before AI 0days is even on the top 50 things to think about.
This is why advice from Google and large company leaders isn’t relevant to most folks out there. Massive scale and attack surface difference. Sure it’s still interesting and fun to speculate at that level, but it’s just not real for most people.
🚨 CRITICAL THREAT ALERT: GLOBAL PAYMENT SYSTEMS BREACH 🚨
🏢 Victim: Verifone
👤 Threat Actor: Handala Hack
🗓️ Date: 2026-03-11
🇮🇱 Origin: Israel (Global Impact)
The threat group "Handala" has announced a sophisticated breach of Verifone, a global leader in payment solutions and Point-of-Sale (POS) terminals. The attackers claim to have successfully disrupted payment systems and terminals worldwide, while simultaneously extracting all related transaction and financial data. This operation is cited as a direct retaliation for ongoing geopolitical strikes.
#ThreatIntel #CyberSecurity #Verifone #DataBreach #FinTech #Handala #InfoSec #CyberAttack #PaymentSecurity
United States 🇺🇸 - LexisNexis has allegedly been breached, exposing 400,000 user profiles, federal judge and DOJ accounts, plaintext AWS secrets, customer passwords, and internal IT infrastructure maps. https://t.co/hLGJ8Cz4Up
Fortinet CVE-2026-24858.. is this even real life anymore?
”An attacker’s valid FortiCloud session, tied to their own device, gets accepted as legitimate for other users’ devices.”
Fortinet FortiGate devices are being targeted in automated attacks that create rogue accounts and steal firewall configuration data.
https://t.co/I18uDsfUhj