EDR killer tool uses signed kernel driver from forensic software
04/02/2026-16:17 04/02/2026-16:25 מחשבים וטכנולוגיה Security Aid דיווח
Hackers are abusing a legitimate but long-revoked EnCase kernel driver in an EDR killer that can detect 59 security tools in attempts to deactivate them. […]Hackers are abusing a legitimate but long-revoked EnCase kernel driver in an EDR killer that