Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Using Minifilters to Disable EDR Systems - A Kernel-Based Attack Technique

Security BSides London via YouTube

Overview

Coursera Plus Monthly Sale: All Certificates & Courses 40% Off!
Watch a 40-minute Security BSides London conference talk exploring advanced offensive security techniques using minifilters to bypass and disable Endpoint Detection and Response (EDR) systems. Learn about EDR architecture fundamentals and components before diving into common minifilter abuse methods for evading file system monitoring. Discover a novel technique for completely disabling EDR agents by preventing access to critical resources through PreOperation callback registration, including detailed kernel-level concepts and implementation steps. Compare the effectiveness of different minifilter exploitation approaches for concealing malicious activities and indicators of compromise. Examine defensive strategies, potential countermeasures, and methods for detecting and mitigating minifilter-based attacks. Conclude with key insights into this sophisticated offensive security approach and participate in an interactive Q&A discussion.

Syllabus

When The Hunter Becomes The Hunted: Using Minifilters To Disable EDRs - Tom Philippe

Taught by

Security BSides London

Reviews

Start your review of Using Minifilters to Disable EDR Systems - A Kernel-Based Attack Technique

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.