2 - Communication with User Mode
Students will learn why an EDR often needs to hand off analysis decisions to user mode when kernel mode cannot safely or efficiently perform full processing. Students will learn practical design patterns for sending event data to a user-mode service and acting on a returned decision.