dimi on Nostr: Ya but we’re not just talking about detections. The agent for each of these still ...
Ya but we’re not just talking about detections. The agent for each of these still needs kernel admin to hook? So you’d have to abuse the deployed agent in most cases, which is too sophisticated for 99.999% of attacks, but the risk is still present, right?
Published at
2024-07-19 15:22:50Event JSON
{
"id": "96eebe79db778d8b05d012d154c1e2a8143e6c5521f895291f9b37d04793d84c",
"pubkey": "1f830dd875130b134fbf3f27a69eecd8613a499748a71b5a271a719febae14ed",
"created_at": 1721402570,
"kind": 1,
"tags": [
[
"e",
"c11e6270f33a491371323e34ca146b2216ac289b1a385b06e1c5e999795ef08d",
"",
"root"
],
[
"e",
"5cf3540ef4d42d3bf090e12fe76fd6f4d48f3a584234ac272e13b5cae1022677",
"",
"reply"
],
[
"p",
"3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24"
],
[
"p",
"7ca66d4166b16f54a16868191ba1c6386a976624f4634f3896d9b6740a388ca3"
],
[
"p",
"3c07d68edf71f6d22374dffae054e6801468594e7b0d0625fb5bcd24b202264d"
],
[
"p",
"32e1827635450ebb3c5a7d12c1f8e7b2b514439ac10a67eef3d9fd9c5c68e245"
],
[
"p",
"6c5fbbb2ed7c3a8df0f17376ad38167bef90ad337d0cc46d26f0ca68620b9a71"
]
],
"content": "Ya but we’re not just talking about detections. The agent for each of these still needs kernel admin to hook? So you’d have to abuse the deployed agent in most cases, which is too sophisticated for 99.999% of attacks, but the risk is still present, right?",
"sig": "71353f7f5fb00805c80b0cc9785978066dabf7f53b3236235599599e36b40c6fe84c15931a218b60b876d60959e407994f2e3ff1559c3d448eee22ac80be454d"
}