RC RANDOM CHAOS

EDR telemetry

6 posts

htop is a reconnaissance surface
Article

htop is a reconnaissance surface

How htop and top expose Linux resource contention - OOM-killer steering, D-state telemetry gaps, niced miners, and PID exhaustion mapped to MITRE T1562 and T1499.

Asahi 7.1 maps the DMA layer under macOS
Article

Asahi 7.1 maps the DMA layer under macOS

Asahi Linux 7.1 exposes Apple Silicon coprocessors, DART IOMMU boundaries, and a silent SMC firmware ABI change - the layer below every macOS EDR agent.

Schrems II broke US data transfers, July 2020
Article

Schrems II broke US data transfers, July 2020

Schrems II (CJEU C-311/18) makes US-hosted EDR telemetry on EU endpoints a restricted transfer. Why data residency now degrades detection fidelity.

This isn't a bug. It's the default.
Article

This isn't a bug. It's the default.

Codex writes unbounded session logs to local SSDs. Mapped correctly to MITRE T1499, not T1071 - a disk-exhaustion DoS primitive EDR baselines miss.

Article

axios CVE-2025-3891: What the Advisories Don't Say About Immutable Images

CVE-2025-3891 in axios allows prototype pollution leading to RCE. This post reveals why deployed container images remain at risk even after patching, due to missing artifact provenance and immutable verification.

Article

Chrome's Renderer Process Vulnerability: Understanding the Exploit Window

Critical vulnerability CVE-2026-1847 in Chrome's renderer process allows remote code execution. Exploitation window exists due to delayed enterprise patching, with telemetry showing memory reads and DNS anomalies but no reliable detection across events.