|
|
|
|
|
by notepad0x90
699 days ago
|
|
they need to be processed in kernel mode where the monitoring happens, user mode EDRs are trivial to bypass. they have to be processed by whatever is going to use them, and in this case it is the "lightweight" sensor code in kernel mode. |
|