3 ms·
In the mitigation section there is written 'Deploy Runtime Protection: Use advanced anti-malware and behavioral detection tools that can detect rootkits, crypto
by opengears 2y ago
In the mitigation section there is written 'Deploy Runtime Protection: Use advanced anti-malware and behavioral detection tools that can detect rootkits, cryptominers, and fileless malware like perfctl.' -- which tools can we currently use to detect perfctl?
- ykonstant 2y agoI hear Crowdstrike is king (≖ ͜ ≖)
- doubled112 2y agoTo be fair, a system that rebooted and won't come back up IS pretty secure.
- AStonesThrow 2y agoNo, because it's a denial of service. C-I-A triad: Confidentiality, Integrity, Availability. A dead system is confidential, and if that's your criterion, then fine, but legitimate users may require access to intact data and services.
- doubled112 2y agoSure, and availability in this sense is often forgotten, but I was only joking about Cloudstrike's ability to block malware. A dead machine is difficult to infect with malware. You'd have to go out of your way to do so.