> or you proxy through your own service where you can ratelimit, inspect, and restrict the traffic
It literally seems like they are doing just that, and the agents are just finding holes in that.
It literally seems like they are doing just that, and the agents are just finding holes in that.
Anything beyond baseline would be observable- silence, malformed packets, too much egress, unusually large packets, etc
If you are using a firewall, you are already doing it wrong. Don’t list thinks to block - list things to allow and make that list small.