{"id":3328,"date":"2024-11-19T07:48:51","date_gmt":"2024-11-19T12:48:51","guid":{"rendered":"https:\/\/increasec.com\/?p=3328"},"modified":"2024-11-19T08:44:55","modified_gmt":"2024-11-19T13:44:55","slug":"ring-fencing","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=3328","title":{"rendered":"Ring Fencing"},"content":{"rendered":"\n<p>Hash based AntiVirus is ineffective in this day of ChatGpt.&nbsp; Bad guys can make custom threats or custom obfuscations.<\/p>\n\n\n\n<p>&nbsp;I expect the future is Ring Fencing.which allows a set of access rules per application.&nbsp; eg we could allow Powershell to only access Privage networks.&nbsp; Now Powershell still works for my company RMM tasks but can&#8217;t fetch Malware from the internet.<\/p>\n\n\n\n<p>The Co. I know with working Ring Fencing is ThreatLocker.\u00a0 Other companies like SentinelOne use them buzz words but only use the data to &#8220;help analysts make better decisions&#8221;  aka doesn&#8217;t block any threats.<\/p>\n\n\n\n<p>Ring fencing is more like behavioural analysis in that it doesn&#8217;t look for a specific hash\/signature (traditional AV) which can be easily changed.  Except it is Program behaviour and not End User behavior which has proven to be rife with false positives<\/p>\n\n\n\n<p>I expect the ruleset needed to make this work will be fiddly but I&#8217;m not seeing a better solution.<\/p>\n\n\n\n<p><a href=\"https:\/\/youtu.be\/gppHq98_Lzk?si=tTvy5oH5oXr9fqH3\">demo<\/a><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hash based AntiVirus is ineffective in this day of ChatGpt.&nbsp; Bad guys can make custom threats or custom obfuscations. &nbsp;I expect the future is Ring Fencing.which allows a set of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3328","post","type-post","status-publish","format-standard","hentry","category-uncategorised"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/3328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3328"}],"version-history":[{"count":5,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/3328\/revisions"}],"predecessor-version":[{"id":3333,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/3328\/revisions\/3333"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}