October 2023
Intermediate to advanced
312 pages
8h 26m
English
Of all the components included in modern endpoint security products, the most widely deployed are DLLs responsible for function hooking, or interception. These DLLs provide defenders with a large amount of important information related to code execution, such as the parameters passed to a function of interest and the values it returns. Today, vendors largely use this data to supplement other, more robust sources of information. Still, function hooking is an important component of EDRs. In this chapter, we’ll discuss how EDRs most commonly intercept function calls and what we, as attackers, can do to interfere with ...
Read now
Unlock full access