Skip to main content

If you don't use #Crowdstrike, you might be wondering if your EDR could burn you the same way.

Not all EDRs use Early Launch Anti-Malware drivers. To find out if yours does, use a registry editor or explorer (Like the great one in Zimmerman's tools) to check out C:\Windows\System32\config\ELAM. If it has live data in it, then something (listed in the hive) is updating signatures for an ELAM driver. If not, no ELAM drivers are present.

in reply to Taggart :donor:

This image from the Windows article about the boot process helps explain the situation. There are other kernel drivers that EDRs can employ, but ELAM happens first. This is why it is both valuable and a dangerous failure point.