Research · Tag · Edr

Posts tagged edr.

1 entry · sorted: recency← All research
RESEARCH
2026-07-23

What syscall-layer tooling cannot see in P2P infrastructure: a technique-by-technique analysis

If you run Falco, an EDR, or a generic host agent on a validator and a network-DoS attack against the node went undetected, this explains why. A technique-by-technique analysis of five reproduced P2P-infrastructure attacks against the syscall detection surface. Zero are detectable as attributable rules, and the reasons are structural, not a matter of tuning.

Simon Morley
Read →13 min read