16 - MDE EDR ETW Analysis using PerfView
16 - MDE EDR ETW Analysis using PerfView
EDR Internals – Research & Development
Module 1: EDR Fundamentals
Module 1: EDR Fundamentals
Module 2: EDR Research Methodology and Practical Analysis
Module 2: EDR Research Methodology and Practical Analysis
Module 3: Building EDR: Foundations
Module 3: Building EDR: Foundations
Module 4: Basic Kernel Driver
Module 4: Basic Kernel Driver
Module 5: Working with IRPs
Module 5: Working with IRPs
Module 6: Kernel Notifications and Callbacks
Module 6: Kernel Notifications and Callbacks
Module 8: EDR Bypass and Evasion
Module 8: EDR Bypass and Evasion
Module 9: Detection Techniques
Module 9: Detection Techniques
Students will learn how to analyze EDR telemetry using ETW and PerfView. This video demonstrates how event visibility informs detection logic and EDR research decisions.