October 2023
Intermediate to advanced
312 pages
8h 26m
English
Sometimes an EDR must implement its own sensor to capture the telemetry data generated by certain system components. Filesystem minifilters are one example of this. In Windows, the network stack is no different.
A host-based security agent might wish to capture network telemetry for many reasons. Network traffic is tied to the most common way for an attacker to gain initial access to a system (for example, when a user visits a malicious website). It’s also one of the key artifacts created when they perform lateral movement to jump from one host to another. If an endpoint security product wishes to capture and perform ...
Read now
Unlock full access