Please follow the Github Repo, This Notion link may die anytime. Github : https://github.com/An0nUD4Y/AV-EDR-Lab-Environment-Setup By : @an0nud4y
An example of things that can be used to emulate certain features that paid edrs have:
SACL - sysmon
HOOKS
Detecting direct/indirect syscalls from usermode
PROCESS/PESCAN
AMSI Provider
ETW-TI/ETW Providers/Consumers -
Microsoft-Windows-RPC
ETW provider to tap into low level RPC events) : https://github.com/HullaBrian/COMmanderKERNEL CALLBACKS -
Capa - Capabilities Scanning
Trace API calls - TinyTracer
Collect Windows Telemetry for Maldev
Free Trials EDR/AV Products
Open Source AV/EDRs
Open Source EDRs Comparison by @dobin
Image Load Events Scanners
Process Memory Scanners
Signature Detection Bypass
Payload delivery Test