Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Avaddon – TDSSKiller Rootkit Scanner Repurposed to Disable AV/EDR

Avaddon Defense Evasion Sentinel
MITRE ATT&CK
Exploitation for Stealth
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (avaddon)
What This Detects
Avaddon repurposes the legitimate Kaspersky TDSSKiller rootkit-removal utility to disable AV/EDR ahead of encryption – a distinctive tool for this purpose compared to the more common GMER/PowerTool combo also in its kit.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName =~ "tdsskiller.exe"
| project Timestamp, DeviceName, ProcessCommandLine, AccountName, FolderPath

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.