(Mini Guide) How to Avoid an EDR (Common doxing method) GTFIHH!!!!!!!!

H

highefforthreads

Send me a guide and i'll rep + comment
Joined
Aug 28, 2026
Posts
324
Reputation
402
How to partially avoid a EDR attack:


Introduction:
Ok so I just learned recently from @Thodian about what an EDR/supenoa is, and i've realized it's a pretty scary thing to think about (might be a corny thing to say but genuinely I didn't even know this was possible 5 days ago 😭😭) Basically how it works is someone buys a hacked government email and then pretends to be law enforcement, then they request information from whatever website they want that has the target on it, and because the attacker usually makes it seem urgent, so the companies give up the information pretty easily which includes ip's, names, credit card info, etc. So for example if someone were to EDR a person on this site, they could get IP or email info. This is a small little guide for those interested for security purposes, but keep in mind I just learned about this and all of this is theoretical and I'm not sure if this counteracts this attack. Correct me if I'm wrong!

What data companies collect:
1. IP address
2. Email/Phone Number
3. Full name
4. Credit Card Info
5. Operating System, Device type, Fingerprint
6. Keystrokes, typing speed
Prob more, I can't think about it right now

Full sign up protocol + Maintenance:
1. Whonix (auto routes traffic through tor) ran through Qubes OS ideally a burner laptop bought in cash (Thinkpad)
2. All signups through tor, javascript disabled, https only, no VPN, if you must use javascript do not minimize/maximize the screen
3. Temp mails/phone numbers for short term logins, protonmail burner for long term keeping (make sure to sign up with the burner using the protocols)
4. Non-identifiable passwords, (random characters best prob)
5. Pay with gift cards (paid in cash) or XMR on non KYC platform with XMR if you need card verification for site
6. Generate usernames + passwords using inbuilt whonix tool, copy and paste rather than typing
7. Automate MAC Address spoofing at boot (Basically change the mac address whenever u open)
8. USB Wifi adapter for hardware isolation
9 For Xenoforo sites requiring IP's to register, I've been looking into a few different methods, but obviously I can't say because it's against policy.

Conclusion:
I think thats all, atleast all I can think of right now. obviously this is a bit over the top but I was trying to think about how to protect against this attack and this is whati i've come up with, but its a pretty interesting topic to look into (Also i'm not trying to seem like some expert I just learned about this a few days ago) LMK if you have any other things to add to this list. Also, the reason it is so over the top is because i'm thinking in terms of multiple edrs, like lets say you signed up with a temp mail on a vpn, theoretically someone could supenoa that VPN address to get real IP, and so on.
 
  • +1
Reactions: Mai Sakurajima.
@monero thoughts?
 
  • +1
Reactions: monero and Mai Sakurajima.
@monero thoughts?
to prevent edr you can simply purchase accounts and only use them on the web app with a VPN/proxy so it doesn't have any of your info publically available
 
  • +1
Reactions: highefforthreads
to prevent edr you can simply purchase accounts and only use them on the web app with a VPN/proxy so it doesn't have any of your info publically available
but someone could edr that account, get vpn ip, then edr the vpn theoretically right?
 
  • +1
Reactions: monero

Similar threads

H
Replies
64
Views
577
highefforthreads
H
qlf
Replies
0
Views
28
qlf
qlf
Lowdimotrucel
Replies
0
Views
26
Lowdimotrucel
Lowdimotrucel
Surfsup
Replies
5
Views
70
Menas
Menas

Users who are viewing this thread

  • HaileyWelshMogs
  • ihatereddit
  • monero
  • UserE_7.random
Back
Top