edr topic
fibratus
A modern tool for Windows kernel exploration and tracing with a focus on security
FullDLLUnhooking_CSharp
Unhook DLL via cleaning the DLL 's .text section
MISP2CbR
Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.
Microsoft-Defender-for-Endpoint-Queries
Microsoft Defender for Endpoint Hunting Queries
Pyramid
a tool to help operate in EDRs' blind spots
KnownDllUnhook
Replace the .txt section of the current loaded modules from \KnownDlls\ to bypass edrs
ttp-bench
Adversary emulation for EDR/SIEM testing (macOS/Linux)
npm-initial-access
Easy to extend initial access scenario to help with EDR testing on Linux and Mac
conference_talks
Slides from various conference talks
SEDR-Internals
Symantec EDR Internals