October 2023
Intermediate to advanced
312 pages
8h 26m
English
Most modern EDR solutions rely heavily on functionality supplied through their kernel-mode driver, which is the sensor component running in a privileged layer of the operating system, beneath the user mode. These drivers give developers the ability to leverage features that are only available inside the kernel, supplying EDRs with many of their preventive features and telemetry.
While vendors can implement a vast number of security-relevant features in their drivers, the most common one is notification callback routines. These are internal routines that take actions when a designated system event ...
Read now
Unlock full access