netero1010 / EDRSilencer

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
MIT License
1.46k stars 185 forks source link

EDR processes blocklist #1

Closed nclv closed 10 months ago

nclv commented 10 months ago

Here are two lists of EDR processes you could add.

I haven't tested the tool yet, but it looks great :)

netero1010 commented 10 months ago

Thank you for sharing the list. I have pushed a new update that includes support for additional EDRs based on the list and other references.