It says "exfiltrated data", and falcon would be able to check if a specific file (sha1 file fingerprint) is present on any other computer with falcon installed. That's not a bad strategy, if WH is desperate, and if they ask other AV companies to do the same.
But presumably hackers wouldn't run SaaS AV on their machines because of the risk of telemetry being reported back to the publisher. Also, wouldn't it make more sense the Microsoft themselves could track files given the amount of DLP features embedded in Windows, and the amount of telemetry that is sent back from Windows 10 and above? And wouldn't it make more sense that if you wanted to track data flows that you'd reach out to an internet backbone provider?
Jump in the discussion.
No email address required.
If anybody believes that post they need to be euthanized
Jump in the discussion.
No email address required.
Red Deer. All of the vaxxies are gonna become zombies by September and there will be mass civil unrest
Jump in the discussion.
No email address required.
More options
Context
It says "exfiltrated data", and falcon would be able to check if a specific file (sha1 file fingerprint) is present on any other computer with falcon installed. That's not a bad strategy, if WH is desperate, and if they ask other AV companies to do the same.
Jump in the discussion.
No email address required.
But presumably hackers wouldn't run SaaS AV on their machines because of the risk of telemetry being reported back to the publisher. Also, wouldn't it make more sense the Microsoft themselves could track files given the amount of DLP features embedded in Windows, and the amount of telemetry that is sent back from Windows 10 and above? And wouldn't it make more sense that if you wanted to track data flows that you'd reach out to an internet backbone provider?
Jump in the discussion.
No email address required.
More options
Context
I get a feeling ruskis wouldn't have that on a disposable vps used for exfiltration that relays the data to their little servers
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context