
AV/EDR Lab environment setup references to help in Malware development
Initially taken from Maldev Academy Discord and added more resources.
Notion Notes : https://an0nud4y.notion.site/AV-EDR-Lab-Env-Setup-130bc870022d8071935cc682d3eb34b9?pvs=4
An example of things that can be used to emulate certain features that paid edrs have:
SACL - sysmon
HOOKS
Detecting manual syscalls from usermode
PROCESS/PESCAN
AMSI Provider
ETW-TI/ETW Providers/Consumers -
KERNEL CALLBACKS -
Capa - Capabilities Scanning
Trace API calls - TinyTracer
Collect Windows Telemetry for Maldev
Free Trials EDR/AV Products
Open Source EDRs
Open Source EDRs Comparison by @dobin

Image Load Events Scanners
Process Memory Scanners
Signature Detection Bypass