Lesson 3 - Detection Reality People and Honey tokens are THE BEST detective tool you have.
Go buy a Thinkst Canary, they detect me more than any multi-million dollar EDR. Period.
Let me clarify something quickly before I get roasted. I am not saying that EDR (Endpoint Detection and Response) agents don’t have a place, it’s just that they have taken over for Anti-Virus for being mostly preventative and response oriented.