
About this episode
In this sponsored interview James Wilson chats with Airlock Digital co-founders David Cottingham and Daniel Schell about how attackers are using LLMs to enumerate EDR detections.
LLMs dramatically reduce the time and specialist labour needed to extract rulesets out of EDR products. What once might have taken months of manual reversing can now be accelerated by “burning tokens”. The takeaway is that defenders increasingly need to assume attackers have visibility into how their endpoint security products work.
Show notes
Get every episode summarized
Each time Risky Bulletin publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Risky Bulletin

Risky Bulletin: Anthropic agents went hacking again
Risky Bulletin

Srsly Risky Biz: America's drivers licence breach is a national security disaste...
Risky Bulletin

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
Risky Bulletin

Between Two Nerds: Can AI defend critical infrastructure?
Risky Bulletin