• partial_accumen@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    4 days ago

    Unless they’re doing app signing or binary examination, some of the methods to “log every app” literally look for an executable name. Renaming “firefox.exe” to “explorer.exe” (an obviously allowed executable name) and then executing it will still run Firefox.

    • Guy Dudeman@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      15 hours ago

      Yeah, I don’t know how they’re doing it. They’re using some “zero trust” system. It’s beyond me.