Question With Intrusion Prevention, can you setup rules that stop Rootkits and Malware from Accessing the Kernel?

Please provide comments and solutions that are helpful to the author of this topic.

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
With Intrusion Prevention, can you setup rules that stop Rootkits and Malware from Accessing the Kernel?
I want to create a rule setup that provides enhanced anti-tampering, but also should stop rootkits.
 

Sandbox Breaker

Level 9
Verified
Well-known
Jan 6, 2022
435
NIPS for network to prevent the exploit, HIPS configured for the local system to prevent spread to the kernal but it's not a matter of IPS.

You need to holistically harden and have good security operations.IPS is a good layers to prevent an exploit or malicious behaviors... but still not a solution.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top