That's not really true at all.
> since it's impossible in every sense of the word
Ok? Lots of things are impossible, and lots of those things are also still very very hard and costly. Hash collisions aren't impossible, and yet here we are, with a world hinging on them being very hard.
> , they can do whatever they want
Not really.
> Most post-exploitation frameworks (prominent example: DanderSpritz) have modules to remove stuff from the windows event logs without leaving traces.
You realize that:
a) DanderSpritz's logic to bypass the event log was a huge deal
b) It's literally an NSA leaked exploit????? Like are you kidding me using an NSA developed exploit as "pretty basic stuff" lol
Sorry but I think I'm gonna stop responding here.