TGViewer
Sec Note Sec Note @secnote · 2.89K subscribers
Post #268 2.39K
Good write-up on building a kernel-based EDR and understanding how Windows telemetry is actually implemented.

Focus is on real detection primitives like:
PsSetCreateProcessNotifyRoutine(Ex) for process lifecycle monitoring

PsSetLoadImageNotifyRoutine for image/DLL tracking

ObRegisterCallbacks for process/thread handle filtering

kernel → user-mode communication via IOCTL + agent design

https://blog.whiteflag.io/blog/from-windows-drivers-to-a-almost-fully-working-edr/
  • 👾 2
More from @secnote
  1. Sep 27, 2026EDR Evasion: Process Injection Without WriteProcessMemory #EDR #maldev
  2. Sep 25, 2026سلام و درود لنگ ظهر جمعه تون بخیر فایل 4 دوره #SEC530 خدمت شما. واقعا طولانی شد 😅
  3. Sep 24, 2026Sec Note pinned a photo
  4. Sep 24, 2026My New Blog Post Evading Sysmon Dns Monitoring In 2026 | binary-win DNSevade : https://git…
  5. Sep 23, 2026Did Sysmon miss the DNS event?👀
  6. Sep 22, 2026fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →