§ Tag
Tag

Control

AU

Bring Your Own Installer: When the EDR Bypass Ships Inside the EDR

Attackers don’t need a vulnerable driver to blind an EDR — they need the agent’s own installer and a window. The durable detection isn’t the kill command, it’s the silence that follows. Here is what that detection looks like the first time you deploy it, and why it floods the SOC before it works.

·
AC

Ubuntu’s userns Mediation Is a Tripwire, Not a Wall

Ubuntu 24.04 enabled AppArmor mediation of unprivileged user namespaces by default, then Qualys published three ways around it. Here’s what the control actually stops, the audit chain that proves it fired, and how to detect abuse without flooding the SOC.

·