What's getting through?

Just a general check-in. What are we seeing that’s landing and making an impact despite defenses? Stealers? Clickfixes? Just a general discussion of the gaps we’re seeing.

I guess I’ll start. I’m seeing a lot more Node.js malware, often with a copy of Node, or with one that the attacker expects is present on the system. The JS is obfuscated to hell, but EDRs don’t seem to mind.