What's the greatest method of improving the signal to noise ratio of detection logic? Prevention
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks for sharing that single exception. There is no perfect form of prevention. WDAC can be used to block execution of LiveKD. If all attackers wanted to shift to LiveKD for dumping, the detection S|N would be incredibly high.
-
Indeed. Strong prevention + strong detection are worth more than the sum of their parts. Because they reinforce each other and set each other up for success.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
.