Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 20, 2026 (about 3 months ago).

people · May 20, 2026

Huntress Details Attacker Methods to Disable AV and EDR Tools

Share the canonical public link.

Share as image

Huntress published a May 18, 2026 blog post on threat actor defense evasion techniques targeting AV and EDR. The post covers BYOVD attacks, Windows Firewall rule abuse, and agent uninstall methods with examples from EDR Killer binary in February 2026 and W-2 malvertising in March 2026. Huntress detections include real-time BYOVD signals and automated firewall remediation. The company secures 2M endpoints and lists 59 processes in its hit list for such threats.

Below validation threshold — auto-passed without scoring

Supporting evidence