Index / Techniques / EDR Unhooking
Technique Record · T1562.001

EDR Unhooking

Publicly-reported instances of EDR Unhooking bypassing endpoint security products. Maintained on the same basis for every technique in the Index.

19
recorded bypasses
9
products affected

Products recorded as bypassed by EDR Unhooking

ProductEntriesHigh-confidenceMost recent
CrowdStrike 422025-12-07
Microsoft 432025-12-05
Palo Alto Networks 202025-10-18
SentinelOne 212025-12-07
Sophos 212025-05-24
Bitdefender 222025-12-07
major EDR vendor (unnamed) 102024-06-11
Elastic 112025-11-06
all major EDR solutions 102025-04-03

All entries

ProductConfidenceDisclosedSource
CrowdStrike high 2025-12-07github.com record →
Bitdefender high 2025-12-07github.com record →
SentinelOne high 2025-12-07github.com record →
Microsoft high 2025-12-05medium.com record →
Elastic high 2025-11-06radar.offseq.com record →
Palo Alto Networks medium 2025-10-18www.brinztech.com record →
CrowdStrike medium 2025-10-18www.brinztech.com record →
CrowdStrike medium 2025-07-13github.com record →
Microsoft medium 2025-07-13github.com record →
SentinelOne medium 2025-07-13github.com record →
Sophos medium 2025-05-24github.com record →
Palo Alto Networks medium 2025-05-24github.com record →
all major EDR solutions medium 2025-04-03medium.com record →
Bitdefender high 2024-11-26scavengersecurity.com record →
major EDR vendor (unnamed) medium 2024-06-11medium.com record →
Sophos high 2023-12-27app.daily.dev record →
CrowdStrike high 2023-07-06inbits-sec.com record →
Microsoft high 2023-06-07www.linkedin.com record →
Microsoft high 2023-06-01github.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.