SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis technical reference poster explores Windows filesystem minifilters, kernel debugging, and filter communication ports from a red team perspective. Designed for advanced operators and researchers, it provides practical WinDbg workflows, structure references, breakpoint techniques, and real-world analysis methods used to understand how modern security products monitor and communicate within the Windows kernel.
Designed for practical use during research and lab work, this poster helps operators navigate WinDbg workflows, inspect defensive telemetry, and analyze Windows kernel communication mechanisms in real time.
This poster has been created as a reference for the SEC665: Advanced Red Team Operations course, co-authored by the Certified Instructor Jonathan Reiter, Karim Lalji, and Kevin Ott.


Jonathan Reiter teaches advanced red team operations and Windows implant development through hands-on labs grounded in real-world experience.
Read more about Jonathan Reiter


















