3 - Service Operation
3 - Service Operation
EDR Internals – Research & Development
Module 1: EDR Fundamentals
Module 1: EDR Fundamentals
Module 2: EDR Research Methodology and Practical Analysis
Module 2: EDR Research Methodology and Practical Analysis
Module 3: Building EDR: Foundations
Module 3: Building EDR: Foundations
Module 4: Basic Kernel Driver
Module 4: Basic Kernel Driver
Module 5: Working with IRPs
Module 5: Working with IRPs
Module 6: Kernel Notifications and Callbacks
Module 6: Kernel Notifications and Callbacks
Module 8: EDR Bypass and Evasion
Module 8: EDR Bypass and Evasion
Module 9: Detection Techniques
Module 9: Detection Techniques
Students will learn how services behave at runtime: how they start, report status, accept control requests, and expose operational state. Students will learn the practical implications of common service configurations and how control and query operations are performed using the standard service-management APIs.