Skip to content

EDR-Redir : a tool used to redirect the EDR's folder to another location.

TwoSevenOneT/EDR-Redir

Repository files navigation

EDR-Redir

EDR-Redir uses a Bind Filter (mini filter bindflt.sys) and the Windows Cloud Filter API (cldflt.sys) to redirect the Endpoint Detection and Response (EDR) 's working folder to a folder of the attacker's choice. Alternatively, it can make the folder appear corrupt to prevent the EDR's process services from functioning.

Command Line Syntax

EDR-Redir.exe bind <VirtualPath> <BackingPath>

To create bind link from VirtualPath to BackingPath

EDR-Redir.exe bind <VirtualPath>

To remove a link that was previously created

EDR-Redir.exe cloud <SyncRootPath> create

To register cloud sync root folder

EDR-Redir.exe cloud <SyncRootPath>

To remove a syncroot that was previously created

Links

Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter

Some EDR/Antivirus have been successfully tested

  • Microsoft Windows Defender
  • Elastic Defend
  • Sophos Intercept X

Demo Video

Youtube: https://www.youtube.com/watch?v=2_tanx7RSUw

☕ Like what I do? You can fuel my creativity with a coffee!

Buy Me A Coffee

READING

Some books you should read to sharpen your cybersecurity skills, especially in offensive security:

Books on Programming and Cybersecurity recommended by Zero Salarium Researchers

Author:

Two Seven One Three

About

EDR-Redir : a tool used to redirect the EDR's folder to another location.

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages