EDR, demystified! Stay a step ahead of attackers with this comprehensive guide to understanding the attack-detection software running on Microsoft systems—and how to evade it.
Nearly every enterprise uses an Endpoint Detection and Response (EDR) agent to monitor the devices on their network for signs of an attack. But that doesn't mean security defenders grasp how these systems actually work. This book demystifies EDR, taking you on a deep dive into how EDRs detect adversary activity. Chapter by chapter, you’ll learn that EDR is not a magical black box—it’s just a complex software application built around a few easy-to-understand components.
The author uses his years of experience as a red team operator to investigate each of the most common sensor components, discussing their purpose, explaining their implementation, and showing the ways they collect various data points from the Microsoft operating system. In addition to covering the theory behind designing an effective EDR, each chapter also reveals documented evasion strategies for bypassing EDRs that red teamers can use in their engagements.
Die Inhaltsangabe kann sich auf eine andere Ausgabe dieses Titels beziehen.
Matt Hand is an experienced red team operator with over a decade of experience. His primary areas of focus are in vulnerability research and EDR evasion where he spends a large amount of time conducting independent research, developing tooling, and publishing content. Matt is currently a Service Architect at SpecterOps where he focuses on improving the technical and execution capabilities of the Adversary Simulation team, as well as serving as a subject matter expert on evasion tradecraft.
„Über diesen Titel“ kann sich auf eine andere Ausgabe dieses Titels beziehen.
EUR 11,38 für den Versand von USA nach Deutschland
Versandziele, Kosten & DauerGratis für den Versand innerhalb von/der Deutschland
Versandziele, Kosten & DauerAnbieter: Bellwetherbooks, McKeesport, PA, USA
paperback. Zustand: As New. LIKE NEW!!! Has a red or black remainder mark on bottom/exterior edge of pages. Bestandsnummer des Verkäufers NS-PB-LN-1718503342
Anzahl: 14 verfügbar
Anbieter: Bellwetherbooks, McKeesport, PA, USA
paperback. Zustand: As New. LIKE NEW!!! Has a red or black remainder mark on bottom/exterior edge of pages. Bestandsnummer des Verkäufers PB-LN-1718503342
Anzahl: 8 verfügbar
Anbieter: moluna, Greven, Deutschland
Zustand: New. Matt Hand is an experienced red team operator with over a decade of experience. His primary areas of focus are in vulnerability research and EDR evasion where he spends a large amount of time conducting independent research, developing tooling, and p. Bestandsnummer des Verkäufers 883674770
Anzahl: 5 verfügbar
Anbieter: PBShop.store UK, Fairford, GLOS, Vereinigtes Königreich
PAP. Zustand: New. New Book. Shipped from UK. Established seller since 2000. Bestandsnummer des Verkäufers DB-9781718503342
Anzahl: 6 verfügbar
Anbieter: PBShop.store US, Wood Dale, IL, USA
PAP. Zustand: New. New Book. Shipped from UK. Established seller since 2000. Bestandsnummer des Verkäufers DB-9781718503342
Anzahl: 6 verfügbar
Anbieter: Kennys Bookshop and Art Galleries Ltd., Galway, GY, Irland
Zustand: New. Bestandsnummer des Verkäufers V9781718503342
Anzahl: 15 verfügbar
Anbieter: GreatBookPrices, Columbia, MD, USA
Zustand: As New. Unread book in perfect condition. Bestandsnummer des Verkäufers 45751777
Anzahl: 15 verfügbar
Anbieter: GreatBookPrices, Columbia, MD, USA
Zustand: New. Bestandsnummer des Verkäufers 45751777-n
Anzahl: 15 verfügbar
Anbieter: Books Puddle, New York, NY, USA
Zustand: New. pp. 312. Bestandsnummer des Verkäufers 26396214876
Anzahl: 3 verfügbar
Anbieter: Biblios, Frankfurt am main, HESSE, Deutschland
Zustand: New. pp. 312. Bestandsnummer des Verkäufers 18396214870
Anzahl: 3 verfügbar