Open cardosec

Case 7C6084 · Blue team / DFIR · L3 Applied

How EDR Works

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Kernel callbacks, ETW (including ETW-TI) and minifilters give process, file, registry and network telemetry.
  2. Detections combine signatures, behavior rules and ML; data is streamed to a cloud backend for hunting.
  3. Response actions: network isolate host, kill process, quarantine file, and collect forensic packages remotely.
  4. Attackers target EDR via user-mode hook unhooking, direct syscalls and BYOVD to kill agents.

If the interviewer pushes back

  • Why are kernel callbacks harder to evade than user-mode API hooks, and how does BYOVD defeat them?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.