How to Ruin Your Weekend: Building a DIY EDR

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A detailed walkthrough of building a custom Endpoint Detection and Response (EDR) system called 'RottenTomato' from scratch. The project demonstrates kernel driver development, process monitoring through Windows callbacks, static analysis of executables, and DLL injection techniques for runtime monitoring. The implementation

21m read timeFrom infosecwriteups.com
Post cover image
Table of contents
I. Entering the VIP Section: Kernel SpaceII. The Old “Hacky” Way: Messing with the SSDTIII. The New “Official” Way: Kernel CallbacksIV. Let’s Get Our Hands Dirty: The SetupV. Our First Driver: The Kernel SpyVI. Implementing Callbacks: The EDR’s Eyes and EarsGet Itz.sanskarr’s stories in your inboxVII. From Kernel Spy to Full-Blown EDRVIII. Conclusion

Sort: