|
|
|
|
|
by hello_moto
705 days ago
|
|
To catch 0day quickly, EDR needs to know "how". The "how" here is AV definition or a way to identify the attack. In CS-speak: content. Catching 0day quickly results in good reputation that your EDR works well. If people turn off their AV definition auto-update, they are at-risk. Why use EDR if folks don't want to stop attack quickly? |
|