
In the last piece I wrote about closing the gap between "attacker gets in" and "attacker detonates" — using a kernel-level access record to see anomalous behavior in real time, and an append-only archive to shrink what's even reachable for…
View original source — Hacker Noon ↗
