"C:\Program Files\Google\Edrgay\EDRGay.exe" as an EDR killer filename - like there’s no other name in their dictionary haha😂
https://t.co/b10CuThbXm
https://t.co/g5FwTt1vkR
@francisco_oca@ShitSecure@m3g9tr0n 4.6 was a massive leap totally agree! i’m just saying that the model is not good enough to operate on its own. hackthebox is not novel, but it is a great baseline for model competency. i will def check out the data you shared :)
@IAMERICAbooted@notajungman i would assume the complementary control would be useful for large enterprises where you have a known trusted cidr block you originate from. curious though