2 - Communication with User Mode

Students will learn why an EDR often needs to hand off analysis decisions to user mode when kernel mode cannot safely or efficiently perform full processing. Students will learn practical design patterns for sending event data to a user-mode service and acting on a returned decision.