Case 9E23A3 · Malware & intel · L5 Expert
How malware evades EDR
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- EDRs see activity via user-mode API hooks in ntdll, kernel callbacks, ETW (incl. Threat-Intelligence), AMSI
- Evasion: direct/indirect syscalls, unhooking ntdll from disk, patching AmsiScanBuffer or EtwEventWrite
- BYOVD: loading a signed vulnerable driver to kill EDR processes or remove kernel callbacks
- Sleep obfuscation and stack spoofing hide beacons in memory between check-ins
- Defenses: driver blocklist (HVCI), tamper protection, ETW-TI telemetry, and alerting on sensor gaps
If the interviewer pushes back
- Why is 'EDR went silent' itself a high-fidelity alert, and how would you build it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.