Case 7C6084 · Blue team / DFIR · L3 Applied
How EDR Works
Practise as: Explain it
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Kernel callbacks, ETW (including ETW-TI) and minifilters give process, file, registry and network telemetry.
- Detections combine signatures, behavior rules and ML; data is streamed to a cloud backend for hunting.
- Response actions: network isolate host, kill process, quarantine file, and collect forensic packages remotely.
- Attackers target EDR via user-mode hook unhooking, direct syscalls and BYOVD to kill agents.
If the interviewer pushes back
- Why are kernel callbacks harder to evade than user-mode API hooks, and how does BYOVD defeat them?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.