EDR Bypass Ransomware – The Gentle Killer Threat Every CISSP Must Know
Jul 22, 2026A ransomware-as-a-service platform known as "the Gentleman" has built a tool called Gentle Killer that disables endpoint detection and response (EDR) software before deploying ransomware — targeting over 400 EDR processes across 48 vendors. In this episode of CISSP Cyber Training, host Sean Gerber breaks down the "Bring Your Own Vulnerable Driver" (BYOVD) technique attackers use to escalate from admin access to kernel-level (Ring Zero) control, slipping beneath EDR visibility entirely.
Sean maps the attack to three CISSP domains: Security Operations (Domain 7), Security Architecture (Domain 3), and Risk Management (Domain 1) — covering everything from the 90/10 affiliate revenue model driving this criminal supply chain to concrete defenses like enforcing HVCI/KMCI, locking down driver allowlists, and building centralized logging that survives an EDR compromise. The core takeaway: no single control is enough — resilient architecture assumes EDR can fail.
A couple of quick notes: I pulled the "117 characters" count from a script, so you may want to double-check it against Kajabi's own character counter before publishing, since counting methods can vary slightly. Also, I wasn't able to verify the episode number ("CCT 358") from the transcript itself — it came from the URL/title context, so please confirm it's correct before it goes live.
CISSP Cyber Training Academy Program!
Are you an ambitious Cybersecurity or IT professional who wants to take your career to a whole new level by achieving the CISSP Certification?
Let CISSP Cyber Training help you pass the CISSP Test the first time!