| ### 9 Detection Rules | Rule | Method | Action | |------|--------|--------| | 1 | Process Name Blacklist (12 names) | **BLOCKS** | | 2 | Command Line Keywords (substring) | **BLOCKS** | | 3 | Reconnaissance Detection | `discard` | | 4 | LSASS Dump Detection (dual condition) | **BLOCKS** | | 5 | PowerShell Analysis (flags) | **BLOCKS** | | 6 | Hash-Based Detection (SHA256, `--signatures`) | **BLOCKS** | | 7 | Hooked API Import Detection (`--profile`) | **ALERTS** | | 8 | ETW Integrity Check | **BLOCKS** | | 9 | PE Structure Analysis (packer/header) | **ALERTS** | | ### Technical Features - **Dual-mode monitoring** - User-mode: Toolhelp32 snapshot polling - Kernel-mode: driver callbacks via `--driver` - **Kernel driver integration** - Process/thread creation callbacks - LSASS handle guard (ObRegisterCallbacks) - Kernel-level process blocking & termination - Overlapped I/O with async event delivery - **EDR hook profiles** - Real hook data from CrowdStrike, Carbon Black, Cylance, Bitdefender, Cortex, Checkpoint - **ETW telemetry** - Custom ETW provider & trace session - Integrity monitoring (tamper detection) |