Evading EDR
No Starch Press,US (Verlag)
978-1-7185-0334-2 (ISBN)
Matt Hand is an experienced red team operator with over a decade of experience. His primary areas of focus are in vulnerability research and EDR evasion where he spends a large amount of time conducting independent research, developing tooling, and publishing content. Matt is currently a Service Architect at SpecterOps where he focuses on improving the technical and execution capabilities of the Adversary Simulation team, as well as serving as a subject matter expert on evasion tradecraft.
Introduction
Chapter 1: EDR-chitecture
Chapter 2: Function-Hooking DLLs
Chapter 3: Thread and Process Notifications
Chapter 4: Object Notifications
Chapter 5: Image-Load and Registry Notifications
Chapter 6: Minifilters
Chapter 7: Network Filter Drivers
Chapter 8: Event Tracing for Windows
Chapter 9: Scanners
Chapter 10: Anti-Malware Scan Interface
Chapter 11: Early Launch Anti-Malware Drivers
Chapter 12: Microsoft-Windows-Threat-Intelligence
Chapter 13: A Detection-Aware Attack
Appendix
Erscheinungsdatum | 14.10.2023 |
---|---|
Verlagsort | San Francisco |
Sprache | englisch |
Maße | 178 x 235 mm |
Themenwelt | Informatik ► Netzwerke ► Sicherheit / Firewall |
Mathematik / Informatik ► Informatik ► Theorie / Studium | |
ISBN-10 | 1-7185-0334-2 / 1718503342 |
ISBN-13 | 978-1-7185-0334-2 / 9781718503342 |
Zustand | Neuware |
Haben Sie eine Frage zum Produkt? |
aus dem Bereich