• partial_accumen
    link
    fedilink
    English
    1
    edit-2
    2 months ago

    Unless they’re doing app signing or binary examination, some of the methods to “log every app” literally look for an executable name. Renaming “firefox.exe” to “explorer.exe” (an obviously allowed executable name) and then executing it will still run Firefox.

    • Guy Dudeman
      link
      fedilink
      English
      12 months ago

      Yeah, I don’t know how they’re doing it. They’re using some “zero trust” system. It’s beyond me.