3 ms·
This is a real problem, especially for InfoSec tools. Many EDR tools, such as MS Defender for Endpoint (or whatever it’s called these days) and Crowdstrike Falc
by MadsRC 4y ago
This is a real problem, especially for InfoSec tools. Many EDR tools, such as MS Defender for Endpoint (or whatever it’s called these days) and Crowdstrike Falcon, include functionality that will scan your local network for devices in order to discover unmanaged devices…
It’s a nightmare from a privacy point, but its also a problem for the InfoSec tools… How do they distinguish between an unmanaged private device on a private network or a unmanaged device on a corporate network?
- oarsinsync 4y ago> its also a problem for the InfoSec tools… How do they distinguish between an unmanaged private device on a private network or a unmanaged device on a corporate network? Trivially, from the simplistic (check IPs and router MACs / SSID in use) to the marginally more advanced (deploy an agent that is only reachable from the corporate network) to determine if the tool should even be running in the first place.