Jessica Entwistle
July 28 2026
Infosecurity Magazine reports that ransomware groups are increasingly using EDR kill techniques to disable endpoint detection and response tools before deploying file encryption. According to Halcyon's latest quarterly ransomware report covering Q2 2026, while overall ransomware attack volumes are declining, attackers are adopting more sophisticated obfuscation and evasion techniques that make detection and response significantly harder. EDR kill techniques involve using legitimate drivers, privilege escalation or kernel-level access to terminate or disable security software before the ransomware payload is executed. This trend reflects a broader shift towards more technically capable ransomware operations that invest in bypassing defensive controls rather than relying on volume or opportunistic targeting.
For UK organisations, this development underscores a fundamental challenge in endpoint security: detection tools are only effective if they remain running and capable of reporting when an attack occurs. Ransomware groups understand this, which is why disabling EDR has become a standard step in many attack chains. The operational impact is that organisations can no longer assume their endpoint security stack will alert them to ransomware activity in time to intervene. If attackers successfully disable EDR before encryption begins, the first indication of compromise may be encrypted files and a ransom note rather than a security alert. This makes pre-ransomware detection, network segmentation, offline backups and resilience planning even more critical than they already were. The trend also highlights that ransomware groups are investing in technical capability and are willing to spend time on reconnaissance, privilege escalation and evasion rather than simply deploying payloads and hoping for the best. This means defenders need to focus on detecting the earlier stages of an attack—initial access, credential theft, lateral movement—rather than relying solely on endpoint tools to catch the final ransomware deployment.
UK businesses should review whether endpoint protection strategies account for the possibility that EDR may be disabled during an attack. Consider whether you have layered detection across network, identity and endpoint layers, so that if one layer is bypassed, others can still provide visibility. Review whether tamper protection is enabled on endpoint security tools and whether alerts are generated when security software is stopped, disabled or uninstalled. Assess whether you have visibility into privileged access, driver installations and kernel-level activity that could indicate EDR kill techniques are being used. Consider whether backup and recovery processes can function independently of endpoint security tools, and whether offline or immutable backups are in place to ensure recovery is possible even if endpoint protection fails. Review whether incident response plans include scenarios where endpoint detection is unavailable, and whether network segmentation and access controls can limit the spread of ransomware even if endpoints are compromised. Finally, assess whether security monitoring focuses on detecting the early stages of an attack, such as unusual authentication activity, lateral movement or reconnaissance, rather than relying solely on endpoint tools to detect the final ransomware payload.
Source: Infosecurity Magazine