To me this looks like an oversight by Microsoft, not an intentional thing, but I’m not sure windows defender ever blocked any drivers through the ELAM callback so I don’t know if this changes much.
Other EDRs: do you use the ELAM blocking functionality or only use it for the cert?
April 3, 2025 at 10:13 AM
To me this looks like an oversight by Microsoft, not an intentional thing, but I’m not sure windows defender ever blocked any drivers through the ELAM callback so I don’t know if this changes much.
Other EDRs: do you use the ELAM blocking functionality or only use it for the cert?