Home » github
Concept image showing SilentButDeadly cutting network connections between EDR and AV agents and their cloud management console while the agents still appear active.

SilentButDeadly Explained: User-Mode EDR Neutralization

SilentButDeadly is an open-source Windows tool that neutralizes EDR and AV visibility by cutting their cloud communications with Windows Filtering Platform filters instead of killing the agents. This article unpacks how SilentButDeadly discovers security processes, applies process-specific network blocks, disrupts services, and what defenders should monitor to detect and withstand similar EDR neutralization techniques.

Read More