My new EDR startup company idea:
- Privacy FIRST! β CASH π΅ only
- No telemetry collection! (Send what feels right for you β₯οΈ π)
- Vendor agnostic, which means it donβt collect nothin π«‘π€
- Guaranteed 100-day SLA response time for critical incidents π π―
@ItsReallyNick not an answer to your Q but, adding spur context filters into very very loose methodology/multiple-event rules where src/dst IPs in the audit logs must meet certain criteria is pretty neat π₯΅π