mirror of
https://github.com/EynaExp/MiMiNi-EDR
synced 2026-08-09 12:06:20 +00:00
main
EDR - Endpoint Detection & Response
A Windows kernel-mode EDR agent that monitors system activity and detects malicious behavior in real-time.
Architecture
The project consists of two components:
Kernel Driver (driver.cpp)
- Registers process and thread creation callbacks via
PsSetCreateProcessNotifyRoutineExandPsSetCreateThreadNotifyRoutine - Implements LSASS protection using
ObRegisterCallbacksto stripPROCESS_VM_READandPROCESS_QUERY_INFORMATIONaccess from LSASS handles - Manages an event queue with IRP-based communication to the user-mode agent
- Supports configurable block rules for process creation
User-Mode Agent (Agent.cpp)
- Communicates with the kernel driver via IOCTLs
- Receives and displays real-time process/thread events
- Implements detection rules for:
- Credential dumping tools (mimikatz, sekurlsa)
- LSASS dump attempts (procdump, Task Manager, comsvcs.dll, rundll32, sqldumper, dumpert, nanodump)
- Suspicious command-line activity
- Can terminate malicious processes via the driver
Detection Rules
| Rule | Description |
|---|---|
| Credential Dumping | Detects mimikatz, sekurlsa, kerberos::list |
| LSASS via procdump | Detects procdump targeting lsass |
| LSASS via Task Manager | Detects Task Manager dump attempts |
| LSASS via comsvcs.dll | Detects comsvcs.dll MiniDump abuse |
| LSASS via rundll32 | Detects rundll32 comsvcs MiniDump |
| LSASS via sqldumper | Detects sqldumper targeting lsass |
| LSASS via dumpert | Detects dumpert.exe |
| LSASS via nanodump | Detects nanodump |
| LSASS via MiniDumpWriteDump | Detects dbghelp/dbgcore abuse |
Block Rules
The kernel driver supports runtime block rules that match on:
- Image suffix - process name match (e.g.,
cmd.exe) - Command-line substring - command-line content match (e.g.,
whoami)
Default block rules:
cmd.exe+whoamicmd.exe+net usercmd.exe+net grouppowershell.exe+mimikatzpowershell.exe+sekurlsa
Build Requirements
- Windows 10/11
- Visual Studio with C++ Desktop workload
- Windows Driver Kit (WDK)
- Test signing enabled (
bcdedit /set testsigning on)
Building
- Open the solution in Visual Studio
- Build the driver project (x64 Release)
- Build the agent project (x64 Release)
Usage
-
Load the kernel driver:
sc create EDRTEST type= kernel binPath= C:\path\to\driver.sys sc start EDRTEST -
Run the agent:
Agent.exe -
The agent will display real-time events and take action on detected threats.
-
Stop and remove the driver:
sc stop EDRTEST sc delete EDRTEST
Project Structure
EDR/
├── src/
│ ├── Agent.cpp # User-mode agent
│ └── driver.cpp # Kernel-mode driver
├── docs/ # Documentation
├── .gitignore
└── README.md
IOCTL Codes
| Code | Value | Description |
|---|---|---|
| IOCTL_WAIT_FOR_EVENT | 0x800 | Wait for next event from driver |
| IOCTL_KILL_PROCESS | 0x801 | Terminate a process by PID |
| IOCTL_ADD_BLOCK_RULE | 0x802 | Add a block rule |
| IOCTL_CLEAR_BLOCK_RULES | 0x803 | Clear all block rules |
| IOCTL_SIGNAL_LSASS_DUMP | 0x804 | Signal LSASS dump detection |
Languages
C++
100%