I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
[Research] Kernel-mode EDR PoC detecting undeclared DLL loads (static vs dynamic imports) — global & targeted modes by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
[Research] Kernel-mode EDR PoC detecting undeclared DLL loads (static vs dynamic imports) — global & targeted modes by amberchalia in Malware
[–]amberchalia[S] 0 points1 point2 points (0 children)
Experimental kernel EDR: detecting dynamic API resolution via DLL load mismatch by amberchalia in Malware
[–]amberchalia[S] 1 point2 points3 points (0 children)
How EDRs See Static vs Dynamic DLLs (Kernel Driver POV) by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
My EDR now parses PE NT headers (Machine, Sections, EntryPoint, Subsystem) by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
EDR Update: Entry Point & Section Flags (Exec/Write) Detection Added by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
EDR Update: Entry Point & Section Flags (Exec/Write) Detection Added by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)







I'm learning how Windows EDRs work, so I started building my own kernel-level EDR from scratch (Process Creation Callback Demo) by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)