Skip to content

Details

This is a hybrid event, and the Zoom link will be shared a couple of minutes before the meeting starts.

Zoom link
https://us02web.zoom.us/j/88065290691?pwd=vbvkaRY3rpmyYfTdWez09bYkgif9kG.1

Topic:
How EDR Tools See Everything (Until They Don’t)

Description:
A quick but comprehensive look into the instrumentation points that Windows provides to Endpoint Detection and Response (EDR) products. We'll explore how EDR solutions collect the telemetry that Security Operations Center (SOC) analysts rely on daily, and examine the impact when attackers disable or tamper with these data sources.
Some of the key topics include AMSI, user-mode hooks, ETW, and the role of kernel drivers in telemetry collection. Don't worry if some of these acronyms mean nothing to you now, hopefully by the end of this talk, they will.
We'll also examine how EDR tools implement key features like network containment using the Windows Filtering Platform (WFP) - and how attackers may be able to abuse or bypass these mechanisms to evade detection and maintain persistence.
You'll hopefully gain a clearer understanding of the mechanisms behind EDR visibility and functionality, and the implications of their compromise.

Bio:
Jacob graduated with a bachelor's degree in Computer Engineering from the University of Hartford in 2021, worked as a SOC Analyst for 5 years, and started as a Security Researcher about 3 months ago.

Venue and Food:
This is a hybrid event!

Virtual: Zoom link will be provided at the time of the meeting.

In-Person: We are meeting at 6:30 pm at Paragus IT at 112 Russell St, Hadley, MA. Please RSVP for pizza and soda count.

Related topics

Events in Hadley, MA
Computer Security
Network Security
Hacking
Information Security
Computer Science

You may also like