Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
- Product
- windows
- Category
- process_creation
- Author
- Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2025-09-24
- Updated
- 2026-07-31
ATT&CK techniques
Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies execution of the EDR-Freeze hacktool by matching process image paths containing EDR-Freeze/EDRFreeze and ending in .exe, optionally further constrained by specific IMPHASH values. Attackers can use EDR-Freeze to interfere with security monitoring by exploiting Windows user-mode behaviors to momentarily suspend security-related processes. The detection relies on Windows process creation telemetry (process image path and, where available, an IMPHASH field) to confirm the binary being run.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Process Execution of EDR-Freeze Tool
id: e2c164bd-0768-42f3-9579-f39177c1d872
status: experimental
description: This rule identifies execution of the EDR-Freeze hacktool by matching process image paths containing EDR-Freeze/EDRFreeze and ending in .exe, optionally further constrained by specific IMPHASH values. Attackers can use EDR-Freeze to interfere with security monitoring by exploiting Windows user-mode behaviors to momentarily suspend security-related processes. The detection relies on Windows process creation telemetry (process image path and, where available, an IMPHASH field) to confirm the binary being run.
references:
- https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html
- https://github.com/TwoSevenOneT/EDR-Freeze
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_edr_freeze.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-09-24
modified: 2025-11-27
tags:
- attack.defense-impairment
- attack.t1685
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|contains:
- \EDR-Freeze
- \EDRFreeze
Image|endswith: .exe
selection_imphash:
Hashes|contains:
- IMPHASH=1195F7935954A2CD09157390C33F8E8C
- IMPHASH=129F58DE3D687FB7F012BF6C3D679997
- IMPHASH=2C617A175D0086251642C6619F7CC8BA
- IMPHASH=8828F0B906F7844358FB92A899E9520F
- IMPHASH=AF76D95157EC554DC1EF178E4E66D447
- IMPHASH=E1B04316B61ACA31DD52ABBEC0A37FD5
- IMPHASH=8B2D5B54AFCFEC60D54F6B31D80ED4A0
- IMPHASH=AB8BB31EDD91D2A05FE7B62A535E9EB7
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_hktl_edr_freeze/info.yml
license: DRL-1.1
related:
- id: c598cc0c-9e70-4852-b9eb-8921af79f598
type: derived