EDR Internals for macOS and Linux - Telemetry Sources and Evasion Techniques
Offered By: BSides SATX via YouTube
Course Description
Overview
Explore the inner workings of Endpoint Detection and Response (EDR) agents for macOS and Linux in this 50-minute conference talk at BSides SATX. Delve into the telemetry sources available to these agents, understanding how they detect malicious behavior and identifying potential evasion opportunities. Compare macOS and Linux telemetry sources to their Windows counterparts, focusing on process creation, authentication, networking, and file activity monitoring. Gain valuable insights for both defenders and attackers, particularly relevant for developers with privileged cloud accounts or access to intellectual property on macOS, and for those managing Linux servers hosting sensitive applications or databases.
Syllabus
2024-06-08, 12:00–, Track 1 UC Conference Rm A
Taught by
BSides SATX
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network