Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
-
Updated
Jan 29, 2026 - C
Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass
EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.
🥶 Freeze EDR/AV processes with ColdWer, using WerFaultSecure.exe PPL bypass to extract LSASS memory on modern Windows systems.
Add a description, image, and links to the edr-freeze topic page so that developers can more easily learn about it.
To associate your repository with the edr-freeze topic, visit your repo's landing page and select "manage topics."