It seems to me that these tools create lots of problems ( slows down the machine significantly in particular, gets things wrong and quarantines processes/machines when it shouldn't, injects itself into processes so changes behaviour, etc ).
The main question I have is : does anyone have an actual instance of such tools detecting something useful ? No one in the office was able to show one.
set JAVA_HOME="what_ever_path"
and asked me to explain this egregious hacking attempt.
Now my m3-ultra MacBook work computer that they gave is a 4000 USD teams/email machine since I prefer to work on computers without spyware.
1) Do you think that an organization should have no protections in place? 2) Why not just work from the machine they provided you, and do everything else on a personal machine?
Do you think Crowdstrike offers protection ?
If you have a point to make, why not just say what you are trying to say; it will be more effective discourse. I am genuinely curious.
I get a call from IT on my work phone. My co-workers hear my end of the conversation:
"No, it's not a bot net. It's just one bot. Yeah, I wrote it and it talks IRC."
Thankfully they left me alone.
It’s different from AV in that it mostly looks at runtime behavior and not signatures.
If I was Alex Jones, I'd go further and blame this on a decade of DEI and fluoride in the water. /s
So it's AV + a firewall? What does it actually do?
All my Linux machines are all quiet when nothing is running. In contrast I go to the bathroom at 10pm or 3am and the work laptop fan is blasting. I've logged and see some other security stuff taking up CPU cycles but it happens at least a few times an hour. I wonder how much electricity the world is wasting with this crap.
When I first got the laptop when I started this job 5 years ago I thought it must be infected with malware because it was always running the fan so I put it in a separate VLAN so it can't attack my home Linux machines. IT told me it is security software. Who knew that the cyber attack would come from inside the security software.
It's like these people have nothing better to do with their time and just absolutely have to have to design and build a product for the sake of it, and then dump it on marketing for > 0 amounts of sales through pretty-much wearing IT departments down. Or in the case of this Crowdstrike thing, through the protection racket known as security audit compliance.
The security tradeoffs don't make sense at all once you understand how it works.
Ssh or winrm are significantly more secure than whatever some security vendor thinks will tick an audit box.
10ft pole is an excellent approach.
I hated it before this incident and I will be bringing this incident up every time it is mentioned.
and mac, and linux
(clarification: FSM refers to an AIIT for SEV)