Interesting. Attackers are abusing a revoked EnCase forensic driver as an EDR-killer to silently terminate 59 security tools in kernel mode, bypassing PPL and legacy signing checks. đź”— https://zurl.co/2l987
#CyberSecurity #EDR #Ransomware #BlueTeam #IncidentResponse












