Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile
Craig Rowland - Agentless Linux Security

@craighrowland

Agentless Linux security. No endpoint agents and no drama. Discuss Linux malware, forensics, intrusion detection, and hacking. Founder @SandflySecurity.

ID: 1050648826946568194

linkhttps://www.sandflysecurity.com calendar_today12-10-2018 07:26:15

4,4K Tweet

10,10K Followers

311 Following

Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

We're at the Red Hat Conference this week in Boston. Come by booth 660 and see how we can help protect your Linux systems without endpoint agents.

We're at the Red Hat Conference this week in Boston. Come by booth 660 and see how we can help protect your Linux systems without endpoint agents.
Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

At the Red Hat conference again today. Come by our booth and see Sandfly Security in action and how we can work on virtually any Linux system or device without deploying endpoint agents.

Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

Just bought my Defcon ticket. I'd love to be able to buy a badge that is just paper and charge me less. I throw electronic badges in the garbage and it's a huge waste. Upsell to people that want the fancy electronic badges.

Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

Agent-based EDR can miss a lot of context of an attack. For instance they may say a log file was written to or accessed, but without knowing what was written it is very hard to know if it was malicious or not. The operator says it's a false positive, but really it's an unknown

Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

LLMs are not perfect, but they are a great technology. I look at them like an insanely good compression algorithm. They have taken a vast a amount of human knowledge and shrunk it down to a size that can run on your computer. Pretty amazing when you think about it.

Craig Rowland - Agentless Linux Security (@craighrowland) 's Twitter Profile Photo

My experience with Waymo in San Francisco is that I'll never use an Uber again if I can help it. Waymo felt safer, didn't have unpredictable drivers and was more relaxing. Cities can't get rid of traditional taxis, Uber, etc. fast enough.

HaxRob (@haxrob) 's Twitter Profile Photo

Newer variants of the #BPFDoor has an interesting modification made that avoids detections looking for processes with raw sockets. The kernel reports SOCK_DGRAM rather then rather loud "SOCK_RAW". Here we have a sample found in the recent SKT telco breach. (1/20)

Newer variants of the #BPFDoor has an interesting modification made that avoids detections looking for processes with raw sockets. The kernel reports SOCK_DGRAM rather then rather loud "SOCK_RAW". Here we have a sample found in the recent SKT telco breach. (1/20)