Initial Access Operations Part 1: The Windows Endpoint Defense Technology Landscape
ID: 90b72d78-8325-58cf-8811-3744dda2a70c
STIX ID: report--90b72d78-8325-58cf-8811-3744dda2a70c
Feed Name: Black Hills Infosec Blog
This article surveys modern Windows endpoint defense techniques used by EDR/XDR—including ETW, kernel notification callbacks, ntdll API hooking, process tree analysis, memory page scanning, call stack tracing, hardware-enforced stack protection (CET/IBT), and vulnerable driver blocklisting—explaining how they hinder initial access and post-exploitation on desktops while noting evasion considerations and blocklist gaps; it also observes that improved endpoint security is pushing attackers toward other vectors such as cloud misconfigurations, collaboration tools, supply chains, and credential abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
