Open in app
Home
Notifications
Lists
Stories

Write
Nick Frischkorn
Nick Frischkorn

Home

About

Mar 30

EDRs & Shellcode Loaders

In this post I have covered the basics of how EDR products work on Windows and techniques to get around them (some source code included). Topics Covered Windows API Call Flow API Hooking & Unhooking Syscalls Kernel Callbacks & User Land ETW Parent Child Process Relationships Static & Dynamic Analysis Execution Methods Credits …

Cybersecurity

13 min read

EDRs & Shellcode Loaders
EDRs & Shellcode Loaders
Nick Frischkorn

Nick Frischkorn

Red Teaming & Pentesting | OSEP, OSCP, CCNA

Following
  • Cedric Owens

    Cedric Owens

  • Kyle Mistele

    Kyle Mistele

  • Circle Ninja

    Circle Ninja

  • Luke Stephens (@hakluke)

    Luke Stephens (@hakluke)

  • Christopher Ross

    Christopher Ross

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable