← LibraryTechnique entry
EDR-CALLBACK-REMOVEDefense Evasion
Kernel Callback Removal
After BYOVD admin, unlink PsSetCreateProcessNotifyRoutine / PsSetLoadImageNotifyRoutine entries for the EDR — process events stop firing.
§ Where this technique fits
EDR-CALLBACK-REMOVE is catalogued under the Defense Evasion tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 4 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01LSASS via procdump / comsvcs.dllseen 1×W-LSASS-PROCDUMP · Credential Access