Security News EDR killer tool uses signed kernel driver from forensic software BleepingComputer Daniel Bender 04 Feb 2026 Hackers are abusing a legitimate but long-revoked EnCase kernel driver in an EDR killer that can detect 59 security tools in attempts to deactivate them.