Microsoft has a fundamental problem in their approach to EOL products: They appear fully patched.
All EOL products should be issued a final gimped patch that never installs correctly so EOL products always show unpatched.
@SwiftOnSecurity Explaining that Win7 devices showed compliant because ESU was not purchased and/or license for ESU not installed. That was fun.
@rasldasl @SwiftOnSecurity obligatory “are you trying to defend against an attacker or against an auditor” goes here
@malwareminigun @rasldasl @SwiftOnSecurity Which one is cheaper to defend against *right now*?
@indigoparadox I think you generally don’t know until it becomes Expensive