netero1010/EDRSilencer
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server. observed · 2026-08-28
Health v2 · maintenance only
17/100
- Activity 0
- Release rhythm 8
- Longevity 70
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 981
- days_rel: 668
- days_push: 668
- n_releases_24m: 1
Adoption not part of the score
1899 stars · 246 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preventing them from reporting security events to their servers. It supports many commercial EDR products and can be executed in-memory from C2 frameworks.
Use cases
- block edr agents from reporting to their server
- silence endpoint detection and response telemetry during red team ops
- add wfp filters to block outbound traffic of a specific process
- enumerate running edr processes on a windows host
- remove wfp filters created by the tool
- test edr resilience against traffic blocking
When to choose
- you are a red teamer or penetration tester needing to suppress EDR alerting during authorized engagements
- you need a lightweight open-source alternative to commercial tools like FireBlock
- you want to block outbound traffic of arbitrary processes via WFP on Windows
When to avoid
- you need a defensive tool to protect or monitor EDR agents
- you require stealth features or C2 integration beyond in-memory PE execution
- your target platform is not Windows 10 or Windows Server 2016+
Facets
cli-tool · maturity active
security networking cli security penetration-testing windows windows cli edr-evasion wfp red-team offensive-security traffic-blocking c2
1 source
- readme: https://github.com/netero1010/EDRSilencer · fetched 2026-08-28 · 79f1af32a8be
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| netero1010/EDRSilencer | main | 17 |
For agents
markdown · JSON · MCP: product_card(name="netero1010/EDRSilencer")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem