Windows Process Execution of EDR-Freeze Tool

Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-09-24
Updated
2026-07-31
title: Windows Process Execution of EDR-Freeze Tool
id: e2c164bd-0768-42f3-9579-f39177c1d872
status: experimental
description: This rule identifies execution of the EDR-Freeze hacktool by matching process image paths containing EDR-Freeze/EDRFreeze and ending in .exe, optionally further constrained by specific IMPHASH values. Attackers can use EDR-Freeze to interfere with security monitoring by exploiting Windows user-mode behaviors to momentarily suspend security-related processes. The detection relies on Windows process creation telemetry (process image path and, where available, an IMPHASH field) to confirm the binary being run.
references:
  - https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html
  - https://github.com/TwoSevenOneT/EDR-Freeze
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_edr_freeze.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-09-24
modified: 2025-11-27
tags:
  - attack.defense-impairment
  - attack.t1685
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|contains:
      - \EDR-Freeze
      - \EDRFreeze
    Image|endswith: .exe
  selection_imphash:
    Hashes|contains:
      - IMPHASH=1195F7935954A2CD09157390C33F8E8C
      - IMPHASH=129F58DE3D687FB7F012BF6C3D679997
      - IMPHASH=2C617A175D0086251642C6619F7CC8BA
      - IMPHASH=8828F0B906F7844358FB92A899E9520F
      - IMPHASH=AF76D95157EC554DC1EF178E4E66D447
      - IMPHASH=E1B04316B61ACA31DD52ABBEC0A37FD5
      - IMPHASH=8B2D5B54AFCFEC60D54F6B31D80ED4A0
      - IMPHASH=AB8BB31EDD91D2A05FE7B62A535E9EB7
  condition: 1 of selection_*
falsepositives:
  - Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hktl_edr_freeze/info.yml
license: DRL-1.1
related:
  - id: c598cc0c-9e70-4852-b9eb-8921af79f598
    type: derived