October 2023
Intermediate to advanced
312 pages
8h 26m
English
While the drivers covered in previous chapters can monitor many important events on the system, they aren’t able to detect a particularly critical kind of activity: filesystem operations. Using filesystem minifilter drivers, or minifilters for short, endpoint security products can learn about the files being created, modified, written to, and deleted.
These drivers are useful because they can observe an attacker’s interactions with the filesystem, such as the dropping of malware to disk. Often, they work in conjunction with other components of the system. By integrating with the agent’s scanning engine, for ...
Read now
Unlock full access