|
|
|
|
|
by lima
160 days ago
|
|
Red teams (internal or consultants) use this sort of tooling in the real world. Their job is to emulate a real, competent threat actor. APTs routinely use high-quality rootkits for EDR evasion. Persistence is actually quite rare nowadays - since it's the most easily detected, red teams usually prefer not to and stay memory-only. |
|