Cyber Security News

RealBlindingEDR Tool That Permanently Turns Off AV/EDR Using Kernel Callbacks

An open-source tool called RealBlindingEDR enables attackers to blind, permanently disable, or terminate antivirus (AV) and endpoint detection and response (EDR) software by clearing critical kernel callbacks on Windows systems.

Released on GitHub in late 2023, the utility leverages signed drivers for arbitrary memory read and write operations, bypassing protections like PatchGuard to target six major kernel callback types. This development raises alarms for cybersecurity professionals, as the tool has been adopted by ransomware groups such as Crypto24 in recent attacks.​

The tool’s creator emphasizes research purposes only, disclaiming any malicious use, while providing detailed implementation insights in a Chinese-language analysis article.

By exploiting vulnerable drivers like echo_driver.sys or dbutil_2_3.sys, RealBlindingEDR gains kernel-level access without triggering immediate detection.

Users download the executable from releases, pair it with a compatible driver, and execute commands like “RealBlindingEDR.exe c:\echo_driver.sys 1” for blinding mode or variants for shutdowns.

Screenshots attached to the repository demonstrate real-time removal of callbacks, allowing file deletions and process terminations that AV tools typically block.​

RealBlindingEDR systematically erases callbacks registered via functions such as CmRegisterCallback(Ex), ObRegisterCallbacks, PsSetCreateProcessNotifyRoutine(Ex), PsSetCreateThreadNotifyRoutine(Ex), PsSetLoadImageNotifyRoutine(Ex), and MiniFilter drivers.

RealBlindingEDR Tool – Clearing Kernel Callbacks

These mechanisms allow AV/EDR solutions to monitor process creation, thread activity, image loading, registry changes, file operations, and object handles. For instance, removing ObRegisterCallbacks eliminates handle protection, enabling ordinary admin users to kill EDR processes that would otherwise resist termination.​

The process involves locating global kernel structures like PsProcessType or FltGlobals through exported functions in ntoskrnl.exe and fltmgr.sys.

It then traverses linked lists of callback entries, nullifying function pointers or rerouting list heads to evade PatchGuard-induced blue screens. Adaptation for Windows 7 to 11 and various servers ensures broad compatibility, with ongoing issues tracked via GitHub.​

Tested against products including 360 Security Guard, Tencent Computer Manager, Kaspersky Endpoint Security, Windows Defender, and AsiaInfo EDR, the tool achieves three key outcomes without halting the target’s main process, preserving communication with central management to avoid alerts.

Blinding mode prevents monitoring of sensitive behaviors like malware drops or privilege escalations. Permanent disablement follows by deleting protected files or registry entries post-callback removal, surviving reboots. Killing is straightforward once object protections vanish.​

Demos show, for example, terminating AV processes via Task Manager and erasing self-protected files, as depicted in repository images of command outputs and before-and-after states.​

While intended for ethical research, RealBlindingEDR’s simplicity, requiring only a signed driver and admin rights, poses risks for red teaming and real-world threats.

Ransomware operators like Crypto24 have integrated it into multi-stage attacks, impairing defenses before encryption. Organizations should monitor for vulnerable driver loads and kernel anomalies using advanced EDR with behavioral analytics.​

Microsoft and AV vendors urge driver signature enforcement and tools like Driver Signature Enforcement Overrider mitigations. Future updates may target ETW providers and WFP callbacks, escalating kernel-level evasion tactics.

Security teams are advised to review endpoint logs for unusual sys file accesses and prioritize least-privilege driver usage.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…

2 hours ago

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

2 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

4 hours ago

FBI Cuts Accenture Contractor Over Unpatched PeopleSoft Flaw Exposing Thousands

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

4 hours ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

4 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

5 hours ago