Lahiri, Arghadeep (2025) EDR Silencers: Prevent, Detect and Remediate. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (849kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (458kB) | Preview |
Abstract
With the abundant increase in attacks to silence EDR and security software’s using Windows firewall misconfiguration and policy misconfiguration is often exploited by malicious actors to maintains stealth nature and disable endpoint protection without triggering any detection from intrusion detection system. While most security products focus on network packets and endpoint threats, underlying firewall misconfigurations are never really validated. This project proposes the design and implementation of host based monitoring system that specifically monitors the Microsoft’s WFP to identify any misconfigured or malicious firewall block rules associated with processes.
The system interprets the Base Filtering Engine (BFE) while using the native BFE APIs to interact with the active firewall filters and extract application identities that links them to Block rules. A baseline concept-based model is implemented where a baseline image of existing WFP block filters are captured on a pre-configured windows machines and stores in a working directory. When a new firewall rule to block network connections of a process, the system compares with the baseline and flags the anomaly to the user. The information is logged in details inside a separate log files and Windows Event Viewer. Thus this model makes it a probable concept for the future.
Evaluating experimentally reveals that the system reliability identifies application-level suppression that included user level and policy level rule creation and distinguishes between baseline and new list. This approach focuses on host level misconfiguration rather than network packet level or kernel level inspection.
The output generated from underlying monitor software reveals vital information about the newly blocked application providing critical visibility into silent firewall tampering and uses WFP as a powerful telemetry source for monitoring misconfigured security rules in firewall.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Mahajan, Kamil UNSPECIFIED |
| Uncontrolled Keywords: | Windows Filtering Platform; Base Filtering Engine; Windows Firewall; Detection; Endpoint Security; Baseline detection model; Host based monitoring; Windows Event logging; System Hardening; Policy tampering; Defensive security Telemetry |
| Subjects: | Q Science > QA Mathematics > Electronic computers. Computer science T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 03 Sep 2026 11:24 |
| Last Modified: | 03 Sep 2026 11:24 |
| URI: | https://norma.ncirl.ie/id/eprint/9802 |
Actions (login required)
![]() |
View Item |
Tools
Tools