Andy Ful
From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Forum Veteran
Yes, in the home environment (against widespread attacks). It can be partially done in businesses by reducing the attack surface. But, the larger/complex the local network (and Internet integration) the bigger are chances of breaches. Nowadays, one has to accept the Zero Trust security model, which assumes that the Enterprise can be compromised. But anyway, the security has to quickly identify the breach, prevent lateral movement and data leak.From what I typically read in malware analysis reports, the malware usually lands in user space, so wouldn't a properly configured HIPS or other such system hardening tool prevent the malware from launching and subsequently gaining elevated permissions?