Open cardosec

Case 9E23A3 · Malware & intel · L5 Expert

How malware evades EDR

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. EDRs see activity via user-mode API hooks in ntdll, kernel callbacks, ETW (incl. Threat-Intelligence), AMSI
  2. Evasion: direct/indirect syscalls, unhooking ntdll from disk, patching AmsiScanBuffer or EtwEventWrite
  3. BYOVD: loading a signed vulnerable driver to kill EDR processes or remove kernel callbacks
  4. Sleep obfuscation and stack spoofing hide beacons in memory between check-ins
  5. Defenses: driver blocklist (HVCI), tamper protection, ETW-TI telemetry, and alerting on sensor gaps

If the interviewer pushes back

  • Why is 'EDR went silent' itself a high-fidelity alert, and how would you build it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.