Does anyone in #infosec remember that image of raw vs most scrubbed data? It was like Raw Event data, Sysmon, EDR, in that order? Something like that?
@fabian_bader @GraemeB I don't :(
I wonder if @olafhartong might know off the top of his head
@nathanmcnulty @fabian_bader @GraemeB doesn’t ring a bell tbh.
Reminds me of this though by @jaredcatkinson
https://posts.specterops.io/introducing-the-funnel-of-fidelity-b1bb59b04036