Skip to content

Commit

Permalink
Quartz sync: Jul 23, 2024, 2:59 AM
Browse files Browse the repository at this point in the history
  • Loading branch information
opfuchs committed Jul 23, 2024
1 parent 1de6865 commit 2332a0c
Showing 1 changed file with 3 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,9 @@ So how do we get all this information (for step 1) and turn it into something ac
With the above considerations in mind, let's now look at how a contemporary EDR is typically structured. While there are a variety of specific EDR architectures, most approximately follow the following four-part schema in their essentials:

1. Telemetry
2. Agent
3. Sensors
4. Detection logic
2. Sensors
3. Detection logic
4. Agent

I largely adopt this schema from Matt Hand's excellent book on EDR evasion, with some minor modifications. [^1] Note that there *are* agent-less approaches to EDR, which we will briefly discuss shortly[^2] For now however, let's consider each component in turn.

Expand Down

0 comments on commit 2332a0c

Please sign in to comment.