YoVDO

EDR Internals for macOS and Linux - Telemetry Sources and Evasion Techniques

Offered By: BSides SATX via YouTube

Tags

Cybersecurity Courses Linux Courses macOS Courses Telemetry Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the inner workings of Endpoint Detection and Response (EDR) agents for macOS and Linux in this 50-minute conference talk at BSides SATX. Delve into the telemetry sources available to these agents, understanding how they detect malicious behavior and identifying potential evasion opportunities. Compare macOS and Linux telemetry sources to their Windows counterparts, focusing on process creation, authentication, networking, and file activity monitoring. Gain valuable insights for both defenders and attackers, particularly relevant for developers with privileged cloud accounts or access to intellectual property on macOS, and for those managing Linux servers hosting sensitive applications or databases.

Syllabus

2024-06-08, 12:00–, Track 1 UC Conference Rm A


Taught by

BSides SATX

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network