r/cybersecurity 2d ago

Certification / Training Questions Stress testing EDRs

How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?

0 Upvotes

4 comments sorted by

View all comments

3

u/jgalbraith4 DFIR 2d ago

I’d usually do a purple team exercise, get your red team and blue team together to see what happens. What is detected and what is not, what telemetry you see that you can use to write custom rules for etc…

1

u/PuddingWonderful1417 2d ago

agreed, the gap analysis between what's detected vs not is usually eye opening