EDR telemetry
6 posts
htop is a reconnaissance surface
How htop and top expose Linux resource contention - OOM-killer steering, D-state telemetry gaps, niced miners, and PID exhaustion mapped to MITRE T1562 and T1499.
Asahi 7.1 maps the DMA layer under macOS
Asahi Linux 7.1 exposes Apple Silicon coprocessors, DART IOMMU boundaries, and a silent SMC firmware ABI change - the layer below every macOS EDR agent.
Schrems II broke US data transfers, July 2020
Schrems II (CJEU C-311/18) makes US-hosted EDR telemetry on EU endpoints a restricted transfer. Why data residency now degrades detection fidelity.
This isn't a bug. It's the default.
Codex writes unbounded session logs to local SSDs. Mapped correctly to MITRE T1499, not T1071 - a disk-exhaustion DoS primitive EDR baselines miss.
axios CVE-2025-3891: What the Advisories Don't Say About Immutable Images
CVE-2025-3891 in axios allows prototype pollution leading to RCE. This post reveals why deployed container images remain at risk even after patching, due to missing artifact provenance and immutable verification.
Chrome's Renderer Process Vulnerability: Understanding the Exploit Window
Critical vulnerability CVE-2026-1847 in Chrome's renderer process allows remote code execution. Exploitation window exists due to delayed enterprise patching, with telemetry showing memory reads and DNS anomalies but no reliable detection across events.