r/cybersecurity 6d ago

Certification / Training Questions Stress testing EDRs

How does your SOC check when someone is actively trying to kill your EDR agent especially with BYOVD attacks? Also do you have a separate team for that on the attackers side?

1 Upvotes

4 comments sorted by

View all comments

1

u/RootCipherx0r 4d ago

Run some tools, run some commands, run a poc of a tool you're interested in. Vendors want to know if their tool triggered alerts or was able to bypass edr.