2026-07-11 22:35:37 +03:30
2026-07-11 22:35:37 +03:30
2026-07-11 22:35:37 +03:30
2026-07-11 22:35:37 +03:30

EDR - Endpoint Detection & Response

A Windows kernel-mode EDR agent that monitors system activity and detects malicious behavior in real-time.

Architecture

The project consists of two components:

Kernel Driver (driver.cpp)

  • Registers process and thread creation callbacks via PsSetCreateProcessNotifyRoutineEx and PsSetCreateThreadNotifyRoutine
  • Implements LSASS protection using ObRegisterCallbacks to strip PROCESS_VM_READ and PROCESS_QUERY_INFORMATION access from LSASS handles
  • Manages an event queue with IRP-based communication to the user-mode agent
  • Supports configurable block rules for process creation

User-Mode Agent (Agent.cpp)

  • Communicates with the kernel driver via IOCTLs
  • Receives and displays real-time process/thread events
  • Implements detection rules for:
    • Credential dumping tools (mimikatz, sekurlsa)
    • LSASS dump attempts (procdump, Task Manager, comsvcs.dll, rundll32, sqldumper, dumpert, nanodump)
    • Suspicious command-line activity
  • Can terminate malicious processes via the driver

Detection Rules

Rule Description
Credential Dumping Detects mimikatz, sekurlsa, kerberos::list
LSASS via procdump Detects procdump targeting lsass
LSASS via Task Manager Detects Task Manager dump attempts
LSASS via comsvcs.dll Detects comsvcs.dll MiniDump abuse
LSASS via rundll32 Detects rundll32 comsvcs MiniDump
LSASS via sqldumper Detects sqldumper targeting lsass
LSASS via dumpert Detects dumpert.exe
LSASS via nanodump Detects nanodump
LSASS via MiniDumpWriteDump Detects dbghelp/dbgcore abuse

Block Rules

The kernel driver supports runtime block rules that match on:

  • Image suffix - process name match (e.g., cmd.exe)
  • Command-line substring - command-line content match (e.g., whoami)

Default block rules:

  • cmd.exe + whoami
  • cmd.exe + net user
  • cmd.exe + net group
  • powershell.exe + mimikatz
  • powershell.exe + sekurlsa

Build Requirements

  • Windows 10/11
  • Visual Studio with C++ Desktop workload
  • Windows Driver Kit (WDK)
  • Test signing enabled (bcdedit /set testsigning on)

Building

  1. Open the solution in Visual Studio
  2. Build the driver project (x64 Release)
  3. Build the agent project (x64 Release)

Usage

  1. Load the kernel driver:

    sc create EDRTEST type= kernel binPath= C:\path\to\driver.sys
    sc start EDRTEST
    
  2. Run the agent:

    Agent.exe
    
  3. The agent will display real-time events and take action on detected threats.

  4. Stop and remove the driver:

    sc stop EDRTEST
    sc delete EDRTEST
    

Project Structure

EDR/
├── src/
│   ├── Agent.cpp        # User-mode agent
│   └── driver.cpp       # Kernel-mode driver
├── docs/                # Documentation
├── .gitignore
└── README.md

IOCTL Codes

Code Value Description
IOCTL_WAIT_FOR_EVENT 0x800 Wait for next event from driver
IOCTL_KILL_PROCESS 0x801 Terminate a process by PID
IOCTL_ADD_BLOCK_RULE 0x802 Add a block rule
IOCTL_CLEAR_BLOCK_RULES 0x803 Clear all block rules
IOCTL_SIGNAL_LSASS_DUMP 0x804 Signal LSASS dump detection
S
Description
Automated archival mirror of github.com/EynaExp/MiMiNi-EDR
Readme
34 KiB
Languages
C++ 100%