2 - Communication with User Mode
2 - Communication with User Mode
EDR Internals – Research & Development
Module 1: EDR Fundamentals
Module 1: EDR Fundamentals
Module 2: EDR Research Methodology and Practical Analysis
Module 2: EDR Research Methodology and Practical Analysis
Module 3: Building EDR: Foundations
Module 3: Building EDR: Foundations
Module 4: Basic Kernel Driver
Module 4: Basic Kernel Driver
Module 5: Working with IRPs
Module 5: Working with IRPs
Module 6: Kernel Notifications and Callbacks
Module 6: Kernel Notifications and Callbacks
Module 8: EDR Bypass and Evasion
Module 8: EDR Bypass and Evasion
Module 9: Detection Techniques
Module 9: Detection Techniques
Students will learn why an EDR often needs to hand off analysis decisions to user mode when kernel mode cannot safely or efficiently perform full processing. Students will learn practical design patterns for sending event data to a user-mode service and acting on a returned decision.