| |
| ▲ | ctoth 3 days ago | parent [-] | | What is weird to me is that you have access to this information at all? It would make sense for the people who use your software ... the IT departments or whatever to have access but why on earth do your engineers need access? What gates access to your customers' machines? What triggers a write-up like this? Hostnames, "machine names" are ... not unique by nature. | | |
| ▲ | cybergreg 3 days ago | parent [-] | | Huntress is a cybersecurity company. They’re specifically hired for this purpose, to protect the company and its assets. As far as unique identifiers go, advertisers use a unique fingerprint of your browser to target you individually. Cookies, JavaScript, screen size, etc, are all used. | | |
| ▲ | ctoth 3 days ago | parent | next [-] | | The article states that the "attacker" downloaded the software via a Google ad, not deployed by their corporate IT. I'm also slightly curious as to if you might be associated with an EDR vendor? I notice that you only have three comments ever, and they all seem to be defending how EDR software and Huntress works without engaging with this specific instance. | | |
| ▲ | cybergreg 3 days ago | parent | next [-] | | Again, threat actors are well aware of what they’re downloading. FWIW I’m an offsec specialist. I spend a lot of time bypassing EDR. Im just shocked at how little this crowd is aware of OpSec and threat intel. I’ll crawl back into my Reddit hole | | |
| ▲ | Sophira 2 days ago | parent [-] | | I'm so sorry you're getting this kind of response. Your input is valuable and I'm learning a lot. |
| |
| ▲ | FreakLegion 3 days ago | parent | prev | next [-] | | If you just want a different source, I can vouch for what cybergreg is saying. Cybersecurity companies aren't passive data collectors like, say, Dropbox. They actively hunt for attacks in the data. To be clear, this goes way beyond MDR or EDR. The email security companies are hunting in your email, the network security companies are hunting in your network logs, so on. When they find things, they pick up the phone, and sometimes save you from wiring a million dollars to a bad guy or whatever. The customer likes this very much, even if individual employees don't. | |
| ▲ | moffkalast 3 days ago | parent | prev [-] | | Yeah they're in full damage control after realizing how out of touch they are when not talking to corporate suits for once. |
| |
| ▲ | 3 days ago | parent | prev [-] | | [deleted] |
|
|
|