@kkarhan Files of that size are typically crafted to exceed EDR/antivirus scan-size limits, causing the engine to bypass inspection altogether.
@hackerworkspace that's kinda wasteful and assumes that said Software isn't counteracting it with like a "Cloud Scanner" that sends that stuff offsite for scanning...
@kkarhan Some EDRs do address this locally through chunked analysis, but it's not universal. In a cloud context, submitting a 700MB sample is simply impractical .

@hackerworkspace shouldn't a 700+ MB on it's own not be considered "sus" and forcibly made non-executeable?

  • Or doesn't Windows to this day nit support #POSIX-esque chmod?