Over the last number of weeks (after the Solarwinds Orion news) there&#;x26;#;39;s been a lot of discussion on how to detect if a server-based applcation is compromised. The discussions have ranged from buying new sophisticated tools, auditing the development pipeline, to diffing patches. But really, for me it&#;x26;#;39;s as simple as saying "should my application server really be able to connect to any internet host on any protocol". Let&#;x26;#;39;s take it one step further and say "should my application server really be able to connect to arbitrary hosts on tcp/443 or udp/53 (or any other protocol)". And when you phrase it that way, the answer really should be a simple "no".
Intelligence View
SOCIAL SHARE CARD GENERATOR