3 ms·
Idea is not to deny permissions to everything but just keep a log on what the agents are doing thats not in line with our permissions and also you have to know
by softie123 4mo ago
Idea is not to deny permissions to everything but just keep a log on what the agents are doing thats not in line with our permissions and also you have to know what they are bypassing so we can put them in deny list later. Very useful when you spawn many agents working in parallel. This is more of an observability tool.
- tenuousemphasis 4mo agoWell at least you'll know why your data was exfiltrated or your systems compromised, even if you can't stop it...
- softie123 4mo agothats exactly what i went for. also I am keeping all the logs compressed so may be i can build something to build later