sans.org – The current endpoint monitoring capabilities we have available to us are unprecedented. Many tools and our self/community-built detection rules rely on parent-child relationships and command-line arg…

Tweeted by @SANSInstitute https://twitter.com/SANSInstitute/status/1262368616256765954

SANS @MIC Talk – Tricking modern endpoint security products – SANS Institute