
The Story Behind Blackout: Abusing Gmer Driver to Terminate Protected Processes
During a ransomware incident response, I noticed a file with a strange name that was retrieved by the team. Upon inspection, it turned out to be a driver. This raised the question "what does a driver have to do with a ransomware incident response?" To understand this, I