Detection Gaps

EDR

A long and scholarly paper comparing the effectiveness of different EDR products

https://www.mdpi.com/2624-800X/1/3/21/htm


The API calls that different EDR products hook. Useful in understanding where the gaps may be in the EDR you've deployed and how it might be attacked

https://github.com/Mr-Un1k0d3r/EDRs


EDR bypass methods

https://s3cur3th1ssh1t.github.io/A-tale-of-EDR-bypass-methods/


Mitre evaluations of EDR against ATT&CK. Somewhat skeptical of a process where so many vendors claim victory

https://attackevals.mitre-engenuity.org/enterprise