Whether you're writing implants, building EDR killers, abusing BYOVD, unhooking kernel callbacks, patching ETW, AMSI bypasses, LOLBins, or doing detection engineering, you need to know how the sensor actually works under the hood.
@0XDbgMan just dropped a full RE teardown of CrowdStrike Falcon's csagent.sys. Save this before it disappears.
If CrowdStrike Falcon is in your environment and you don't know how it works at the kernel level, you're operating blind on both sides of the engagement.
https://t.co/rqhDgni7tP
#Infosec #ReverseEngineering #MalwareAnalysis