discovered 03 Aug 2026
ColdWer
→ View on GitHubColdWer is a cybersecurity tool that enables users to freeze endpoint detection and response (EDR) or antivirus (AV) processes by leveraging the WerFaultSecure.exe PPL bypass, allowing for the extraction of LSASS memory on modern Windows systems. Its primary use case is for security assessments and exploit development, featuring a fast execution model, manual process control, and the ability to bypass process protection via in-memory modifications. This tool is particularly useful for maintaining stealth during sensitive operations while extracting potentially credential-related information from LSASS.