Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

NoEscape – TDSSKiller Rootkit Scanner (Inherited Avaddon Toolkit, Unconfirmed)

Noescape Defense Evasion Sentinel
MITRE ATT&CK
Exploitation for Stealth
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
public reporting attributing NoEscape to the Avaddon codebase (technique unconfirmed for NoEscape specifically); ransomware.live group profile (noescape)
What This Detects
NoEscape is widely attributed (Group-IB, Cyble) to a rebrand of the Avaddon codebase after Avaddon's 2021 shutdown. Avaddon's confirmed use of TDSSKiller to disable AV/EDR is a plausible but unconfirmed inherited technique for NoEscape specifically.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName =~ "tdsskiller.exe"
| project Timestamp, DeviceName, ProcessCommandLine, AccountName, FolderPath

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.