An unexpected journey into Microsoft Defender's signature World
retooling.io
retooling.io
https://html.spec.whatwg.org/multipage/text-level-semantics....
EPPs will consist of threat detection and response (EDR), as well as proactive prevention, vulnerability management, threat intelligence, data-loss prevention, encryption management, etc.
The R stands for Response.
Did a bit of red teaming around the topic of reverse shells and privilege escalation and was pleasantly surprised, how much Windows Defender catches. Our IT Department recently switched away from a paid McAfee service doing end point security, which failed to detect unauthorized access in many instances.
Also, I totally read the intro as "addressing the ERP use-case"
To your point about reverse shells, last time I tried about 2 years ago, meterpreter was still sneaking past almost everything. There are some tools on Github for detecting it, but it is very good at evading detection in general.
Did something else detect them in a timely manner, or did you find evidence later as part of some sort of audit?
(or was the inadequacy found via staged penetration testing?)