Zack
Zack

@z_ack@infosec.exchange

Giving social media another go. I'm not very good at this.

July 17, 2025
Show Full thread

I get a lot of confused and angry teams when I inject EDR disablement into IR tabletop exercises. But it’s something I see in real life every week. You need to monitor for agent crashes and fall off. You can’t rely on EDR as a lone panacea for defense and forensics.

Older posts from other instances may not be displayed.
Open in original site

Elk Logo

Welcome to Elk!

Elk is a nimble Mastodon web client. You can login to your Mastodon account and use it to interact with the fediverse.

Expect some bugs and missing features here and there. Elk is Open Source and we're actively improving it as a community project. Join us and let's build it together!

If you'd like to report a bug, help us testing, give feedback, or contribute, reach out to us on GitHub and get involved.

To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!

PatakTAKAHASHI ShuujiAnthony Fu三咲智子 Kevin DengJoaquín SánchezDaniel Roe

The Elk Team