I've put up a blog on the DigiCert incident as well as the Microsoft definition false positive. This includes some analysis and VT links to samples that have actually been signed by the compromised certificates. https://t.co/e2eQHpwPcm
Video showing how @AirlockDigital prevents TTPs such as the DLL search order used to load an attacker controlled DLL into a trusted application from the compromised CPU-Z website last week.
https://t.co/u3q3ptN6AT
Signature-based control breaks down with agentic AI.
Block one path → it tries another. Different method. Same outcome.
That’s why control needs to be on the endpoint - and focus on capability AND execution.
My blog (with videos) here:
https://t.co/vfud5Ppfga
Excited to attend our first #FalConEurope, meeting our existing partners and customers in the region and showing the @CrowdStrike community how we make allowlisting achievable.
We’re excited to announce our Platinum sponsors for #Sekurokon2024: @AirlockDigital, @CrowdStrike and @Netskope! Join us to explore cutting-edge tech in endpoint, network, data, cloud security & threat intelligence. Contact your #Sekurian account manager to register!
Last year, 93% of breaches within APAC were a result of vulnerability exploitation. How can we then leverage application controls as a proactive defence? #Sekuro and @AirlockDigital co-hosted a roundtable yesterday to discuss.
I've created a few tools to help with onboarding and maintaining an @AirlockDigital instance, mainly to do with bulk adding rules, and comparing your current rule set to historic executions (to see if you missed anything)
https://t.co/WL85jWBQew
@Harvesterify@techspence@AirlockDigital has agents for Linux and Mac. Allowlisting is traditionally difficult on Linux because files aren’t signed, we created a mapping between yum/apt databases to provide publisher trust on Linux. We have drivers for older kernels, and driverless using fanotify api.
Love reading new @AirlockDigital case studies as they are published. EQT is North America's largest natural gas producer. Many more in the pipeline - https://t.co/9Xwa4MApGS
The “Allowlist Auditor” from @AirlockDigital is great to highlight the current state of allowlisting on endpoints. Includes tests for execution (exe, dll, PS1, CPL and others) in common locations, and an audit for existing allowlisting solutions. https://t.co/iU3BhPeF90
We are less than a week away September 18 through September 21, we will be present at CrowdStrike's Fal.Con 2023 as a Gold Sponsor. Join us at Caesars Palace in Las Vegas, to get more details about our allowlisting platform.
Used our slot on @riskydotbiz news with
@campuscodi to deep dive the vulnerable driver landscape, Microsoft security boundaries, byovd, loldrivers and why/which actors benefit from their use. Interested in community feedback. Listen here: https://t.co/9l64b5uS6h