Skip to content

Microsoft to nudge EDR out of the kernel

Currently antivirus firms use a range of Windows kernel drivers to do things like intercept network and file process activity

Microsoft to nudge EDR out of the kernel
Sometimes stock image choices are hard, OK?

Microsoft is gearing up to nudge EDR vendors out of the Windows kernel – a move that follows  CrowdStrike's failure to spot a bug that caused its agent (running in kernel mode) to crash over eight millions computers.

Redmond will release a new Windows endpoint security platform in private preview next month that will see “security-product developers… build their products outside of kernel mode,” it confirmed on June 25.

That’s part of an architectural overhaul that Microsoft is making much of being a collaborative industry effort with multiple EDR vendors: It names Bitdefender, CrowdStrike, ESET, SentinelOne, Trellix, Trend Micro, and WithSecure as members of its “Windows Resiliency Initiative” (WRI).

It will require some real product innovation by partners...

This content is for paying members only

Subscribe
Add The Stack on Google