Hunting malware and malicious MCPs in memory on Kubernetes with FleetDM + Osquery + YARA

As a threat detection engineer, I’ve always wanted the ability to scan for malware in memory at scale. As an Osquery fanboy, I frequently tinkered with the idea of integrating memory forensics into Osquery but was unsuccessful. Recently, Osquery and Fleet introduced new capabilities to scan memory at scale with YARA rules.  The new yara_process … Continue reading Hunting malware and malicious MCPs in memory on Kubernetes with FleetDM + Osquery + YARA