Starting anomaly detection for threat hunting can be frustrating. Users do strange things on their systems. Whatever you can imagine, reality is much worse.pic.twitter.com/3AaIKEKDi9
-
Show this thread
-
Replying to @cyb3rops
Some devs are even worse . If my memory serves me right Amazon Assistant launches via a .hta! Why on earth!
1 reply 0 retweets 1 like -
Replying to @ngiannoulis @cyb3rops
Also TeamViewer and a lot of printer-config managers. But especially TeamViewer: why?!?
1 reply 0 retweets 0 likes
maybe because you can hijack what driver it will install as system service?
4:59 PM - 20 Jan 2021
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.