YouTube Video
You will learn how to navigate your way around and enumerate filesystem minifilters that might be part of the trickery behind modern security products.
Once done, you will be able to harness the power of dx commands, along with other debugger extensions. In just two hours, you will know how to begin your journey.
This workshop continues the Intro to WinDbg series and serves as a recommended prerequisite for SEC665: Advanced Red Team Operations. Students will learn how to enumerate and inspect filesystem minifilters, explore filter communication mechanisms, and begin understanding how modern security products generate visibility within the Windows kernel.
Through practical demonstrations and guided workflows, attendees will build confidence with WinDbg, debugger extensions, and kernel structures before encountering the advanced kernel research topics covered in SEC665 Day 5. For operators looking to better understand defensive telemetry, kernel visibility, and the foundations of EDR research, this workshop provides the ideal starting point.
Learn more about your presenter, Jonathan Reiter: https://www.sans.org/profiles/jonathan-reiter
This workshop is intended to serve as a recommended prerequisite for SEC665: Advanced Red Team Operations and will help students prepare for the advanced kernel debugging and research concepts introduced in the course. To learn more, browse upcoming sessions, and access your free course preview, visit https://www.sans.org/sec665

SOCIAL SHARE CARD GENERATOR