Hey everyone, saw the news about that new supply chain attack targeting CI/CD pipelines. It got me thinking.
I'm just starting with cloud security, but my team uses Intercept X. I know it does memory scanning for ransomware, but would it catch something like this? The attack seems to inject malicious code during a build process, and the payload might only be in memory briefly before it executes. Does the memory scanning look for these kinds of patterns, or is it mostly for known ransomware signatures?
Trying to map the theory to what I see in our AWS console. If the malicious code ends up running on, say, a build agent EC2 instance, would Intercept X's EDR piece even be installed there? Or is it more for end-user workloads? 😅
Sorry if this is a basic question! Just trying to understand how the pieces fit together.