Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
soc-investigation-powershell-edrfreeze — SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment. | Kitploit
Tools/GitHubGitHub/zedocun/soc-investigation-powershell-edrfreeze
Defensive ToolsIndicator of Compromise (IOC) ManagementPrivilege EscalationIDS/IPS EvasionMalware AnalysisDigital ForensicsThreat IntelligenceLearning & EducationIncident Response

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
GitHubzedocun/soc-investigation-powershell-edrfreeze

soc-investigation-powershell-edrfreeze

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.

View Repository
1166 months agoNot yet reviewed
Share

Read on Medium

PowerShell EDRFreeze Investigation (LetsDefend Case Study)

This repository contains a documented SOC investigation based on a LetsDefend scenario involving suspicious PowerShell activity, a GitHub-hosted payload, and execution of the EDRFreeze tool.

What this repository includes

  • Full report: report.md
  • Timeline: timeline.md
  • Indicators of compromise: iocs.md
  • MITRE ATT&CK mapping: mitre.md
  • Investigation screenshots: screenshots

Case summary

The investigation identified a PowerShell-driven attack chain in which the host resolved github.com, downloaded EDR-Freeze_1.0.zip, created a temporary __PSScriptPolicyTest file during execution policy evaluation, executed EDR-Freeze_1.0.exe, and then spawned WerFaultSecure.exe.

Attack diagram

Attack Chain

Notes

This case study is based on a LetsDefend training scenario and is published for portfolio and learning purposes.

Download Tool