Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

EDR Internals for macOS and Linux - Telemetry Sources and Evasion Techniques

BSides SATX via YouTube

Overview

Explore the inner workings of Endpoint Detection and Response (EDR) agents for macOS and Linux in this 50-minute conference talk at BSides SATX. Delve into the telemetry sources available to these agents, understanding how they detect malicious behavior and identifying potential evasion opportunities. Compare macOS and Linux telemetry sources to their Windows counterparts, focusing on process creation, authentication, networking, and file activity monitoring. Gain valuable insights for both defenders and attackers, particularly relevant for developers with privileged cloud accounts or access to intellectual property on macOS, and for those managing Linux servers hosting sensitive applications or databases.

Syllabus

2024-06-08, 12:00–, Track 1 UC Conference Rm A

Taught by

BSides SATX

Reviews

Start your review of EDR Internals for macOS and Linux - Telemetry Sources and Evasion Techniques

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.