
AV/EDR Lab environment setup references to help in Malware development
Initially taken from Maldev Academy Discord and added more resources.
Notion Notes : https://an0nud4y.notion.site/AV-EDR-Lab-Env-Setup-130bc870022d8071935cc682d3eb34b9?pvs=4
An example of things that can be used to emulate certain features that paid edrs have:
SACL - sysmon
HOOKS
Detecting manual syscalls from usermode
PROCESS/PESCAN
AMSI Provider
ETW-TI/ETW Providers/Consumers -
KERNEL CALLBACKS -
Capa - Capabilities Scanning
Trace API calls - TinyTracer
Collect Windows Telemetry for Maldev
Free Trials EDR/AV Products
Open Source EDRs
Open Source EDRs Comparison by @dobin

Image Load Events Scanners
Process Memory Scanners
Signature Detection Bypass
EDR Internals
EDR Internals / Working Talks
EDR Telemetry - Various EDR Telemetry : https://github.com/tsale/EDR-Telemetry
Defender Harvester : https://github.com/olafhartong/DefenderHarvester
EDR Hooks Lists : https://github.com/Mr-Un1k0d3r/EDRs
Polonium : A tool from Modern Initial Access and Evasion Tactics course by Binary-Offensive (@mariuszbit). https://github.com/sponsors/mgeeky
EDR Hooks Telemetry
Gartner’s Magic Quadrant for EDR Platforms
<img src="https://raw.githubusercontent.com/An0nUD4Y/AV-EDR-Lab-Environment-Setup/main/Images/Gartner"s-Magic-Quadrant.png" alt="Gartner's-Magic-Quadrant" width="500"/>