Warning: Some posts on this platform may contain adult material intended for mature audiences only. Viewer discretion is advised. By clicking ‘Continue’, you confirm that you are 18 years or older and consent to viewing explicit content.
It needs that kind of access to fight advanced attacks.
It would surprise me if similar EDR programs didn’t have similar access on Linux systems, for example.
It needs that kind of access to fight advanced attacks. It would surprise me if similar EDR programs didn’t have similar access on Linux systems, for example.
No, you make a management API for security products that run in user space as root, you don’t use kernel modules.
Is that the way that EDR is implemented on Linux or are you guessing?