3 ms·
In theory you could maybe use this to kill some endpoint agent used for security monitoring in a way that, if someone were to go investigate the crash, maybe th
by staticassertion 4y ago
In theory you could maybe use this to kill some endpoint agent used for security monitoring in a way that, if someone were to go investigate the crash, maybe they wouldn't immediately think "oh shit, someone killed it".
Attackers do kill those agents, absolutely, but you'd have to be root to kill the agent with this method (and ideally any method), at which point endpoint instrumentation and forensic artifacts are unreliable anyway. Any logs that someone were looking at that said "attacker killed me" could just be deleted/ rewritten. The attacker could even rewrite them on the fly and ship them off the box so you're none the wiser :)