Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence

Praetorian Inc. has introduced Swarmer, a tool designed to enable low-privilege attackers to maintain Windows registry persistence while bypassing Endpoint Detection and Response (EDR) systems.

Praetorian Inc. has introduced Swarmer, a tool designed to enable low-privilege attackers to maintain Windows registry persistence while bypassing Endpoint Detection and Response (EDR) systems.

Swarmer has been operational since February 2025. It utilizes mandatory user profiles and the Offline Registry API to modify the NTUSER hive without triggering standard registry hooks. Traditional methods using HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run keys are easily detected by EDR tools, which hook into APIs like RegSetValue.

Swarmer circumvents this by exploiting mandatory user profiles, a legacy Windows feature. In these profiles, the NTUSER.MAN file, if present, overrides the standard NTUSER.DAT hive upon login. Low-privilege users can create NTUSER.MAN by copying and renaming NTUSER.DAT.

Editing the loaded hive typically requires standard APIs, which alert EDR. Swarmer uses Offreg.dll, Microsoft's Offline Registry Library, to manipulate the hive offline, avoiding standard registry operations that could trigger detection.

Export HKCU using reg export or TrustedSec’s reg_query Beacon Object File (BOF) to avoid creating disk artifacts. Modify the exported registry file, such as by adding Run key entries. Execute Swarmer with the command: swarmer.exe exported.reg NTUSER.MAN or with startup flags: swarmer.exe --startup-key "Updater" --startup-value "C:\Path\To\payload.exe" exported.reg NTUSER.MAN . Place NTUSER.MAN into the %USERPROFILE% directory.

For Command and Control (C2) implants, parse BOF output directly: swarmer.exe --bof --startup-key "Updater" --startup-value "C:\Path\To\payload.exe" bof_output.txt NTUSER.MAN .

Swarmer is developed in C# to facilitate P/Invoke operations and offline usage. It functions as an executable or PowerShell module:

Import-Module '.\swarmer.dll' Convert-RegToHive -InputPath '.\exported.reg' -OutputPath '.\NTUSER.MAN'

It utilizes mandatory user profiles and the Offline Registry API to modify the NTUSER hive without triggering standard registry hooks.
Daniel Brooks · Thehackingpost

A workaround involves using RegLoadAppKeyW to create a base hive, which Offreg then populates.

Feature Details

Platforms Windows 10/11

Privileges Low (user-level)

Evasion No Reg* APIs; optional no-disk BOF

Payload Types Run keys, custom registry modifications

Limitations and Detection Opportunities

Caveat Impact

Advertisement

One-shot Cannot update without admin rights; profile becomes mandatory, resetting user changes.

Login-required Activates only on logout/login; persists through reboots.

HKCU-only No access to HKLM.

Edge cases Potential login corruption; testing advised.

Detection strategies include monitoring for NTUSER.MAN creation outside of enterprise tools, observing Offreg.dll loads in non-standard processes, and identifying profile anomalies. Execution of payloads at login is visible unless obfuscated.

Defenders are advised to monitor user profile directories for NTUSER.MAN files, establish baselines for Offreg usage, and assess profile integrity at login. Swarmer underscores the need to scrutinize legacy Windows features that predate contemporary EDR solutions.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories