With the latest release of Windows Sensor 2026.1, we introduced further tamper protection capabilities in our XDR products for Windows, including WithSecure EDR and WithSecure MDR.
With the rise of “EDRSilencers” being used to block communications from XDR to the backend systems, we have introduced a secondary way of communicating to the WithSecure servers. If the network connection to our sensor gets blocked, automatic steps are taken to restore communication.
In addition, we also will send an event of type “emergency_event” to inform the backend about changes made to the windows firewall.
Actions needed:
If you, as an administrator are monitoring your processes in the systems - make sure to update your monitoring and alerting to facilitate this new use case.