How EDRs work and how to bypass them - Processus 🇫🇷

Описание к видео How EDRs work and how to bypass them - Processus 🇫🇷

I would like to speak about how Endpoint Detection and Response (EDR) softwares work and how to defeat every protection, such as AMSI, Sysmon, DLL Hooking or ETW.

The goal of this talk is to allow a good understanding of these protections IN FRENCH, because many presentations on this subject are only in english.

I would like to present according to the following plan : – Process Hollowing and PE Injection – AMSI Bypass – .NET Reflection – Unhooking DLL – Sysmon unloading – ETW Patching

leHACK website: https://www.lehack.org
leHACK's twitter:   / _lehack_  
leHACK instagram :   / _lehack_  

Комментарии

Информация по комментариям в разработке