<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>EDR Internals on DEATH.sk</title><link>http://death.sk/categories/edr-internals/</link><description>Recent content in EDR Internals on DEATH.sk</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 30 Aug 2026 19:12:00 +0200</lastBuildDate><atom:link href="http://death.sk/categories/edr-internals/index.xml" rel="self" type="application/rss+xml"/><item><title>Why does Palo Alto use a rule engine from the '80s?</title><link>http://death.sk/posts/clips_detection_engine/</link><pubDate>Sun, 30 Aug 2026 19:12:00 +0200</pubDate><guid>http://death.sk/posts/clips_detection_engine/</guid><description>&lt;p&gt;Recently a &lt;a href="https://web.archive.org/web/20260629035415/https://blog.otterpwn.com/projects/heavener"&gt;blog post&lt;/a&gt; came to my attention. The author (otterpwn) presents a tool, called heavener, where they rip detection engines and ML classification models from various EDRs and duct-tape them together. They were able to achieve a very realistic emulation framework of what EDR agents are capable of detecting directly on the machine without relying on cloud components. Unsurprisingly, the blog post was quickly removed. In my opinion, this idea is a welcomed breath of fresh air in offensive research. I highly recommend reading the blog post while it&amp;rsquo;s still available on the Wayback Machine (too late it&amp;rsquo;s excluded now&amp;hellip;).&lt;/p&gt;</description></item></channel></rss>