This seems more like a Sales pitch vs a technical talk.
@mcmurm113 жыл бұрын
The guy in the suit might sound pushy but he's asking the important questions when dealing with an agent with a kernel hook. Wish more people had this technical depth when evaluating products.
@MrDomibella3 жыл бұрын
I agree. Kernel changes are a concern. However, the agent based approach has many more advantages over agent-less. Process level visibility outweighs any "attack surface" concerns.
@rikherlaar2 жыл бұрын
@@MrDomibella Yes also the question on TPS (something we benchmark stateful security devices against traditionally) was very astute in my view. Obviously Host Based -FW's will see less stress than central FW or WAFS but still....
@rikherlaar2 жыл бұрын
I am still struggling to map out these type of solutions again EDR/NDR/XDR and SOAR , in the end we would like to see intent based security policy mgmt wedded with automated detection and response. Basically want to avoid having to install multiple agents (e.g. Sentinel One for EDR and Guardicore to assume a richer form of host based Firewalling - just thinking out loud here...
@newyork16558 ай бұрын
I am confused , it’s windows independent but it’s designed for windows ? What is that mean ?