Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
P38
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
P38
8y ago
Freehunter, grateful for your thoughts on the below in response to your comment about technical staff running esoteric and constantly changing apps and therefore whitelisting isn't always possible. Can apply prevention for PowerShell,
2.
▲
by
P38
8y ago
Not all next-gen endpoint solutions do this. An endpoint application execution control can be much simpler. 1. Choose an existing trust list (over 1000 apps/dlls etc trusted) or build your own in a few minutes. 2. Install file filter d
3.
▲
by
P38
8y ago
No claims that it is sufficient - what is does do it prevent any non-trusted file based executable etc from running. Doesn't do fileless, memory-based or rootkit but does prevent any untrusted and therefore unknown executable from runn
4.
▲
by
P38
8y ago
Not at all, zero days are of course found in trusted code. But they are used to inject malware (file based). That malware is not on the trust list and therefore is blocked from executing. For example - what turned out to be a zero day exp
5.
▲
by
P38
8y ago
We are talking about file-based malware that needs to execute. It doesn't mean this hash hasn't been seen before, it means that application X which is trusted, is on the trust list (and yes, fingerprinted by 6 hashes) is allowed t
6.
▲
by
P38
8y ago
Next gen AWL/Endpoint solutions offer a simple and true default deny approach. Either an app (executable, script, dll) is trusted or it isn't. If it is not trusted it can't run - period. 100% successful at preventing zero