Detection Gaps
Detection Gaps
EDR
EDR
A long and scholarly paper comparing the effectiveness of different EDR products
https://www.mdpi.com/2624-800X/1/3/21/htm
The API calls that different EDR products hook. Useful in understanding where the gaps may be in the EDR you've deployed and how it might be attacked
https://github.com/Mr-Un1k0d3r/EDRs
EDR bypass methods
https://s3cur3th1ssh1t.github.io/A-tale-of-EDR-bypass-methods/
Mitre evaluations of EDR against ATT&CK. Somewhat skeptical of a process where so many vendors claim victory
Windows Defender
Windows Defender