Tag:red teaming

Ibai Castells explains how moving from high level Windows APIs to lower level syscall usage alters what EDRs observe. It outlines the trade offs and gives non-actionable guidance for defenders on telemetry and mitigation.