
The last problem are the trust me bro inte integrity checking tools. Um Ivanti is a big offender in that regard. Um basically they have a tool running on the appliance itself uh which you can tell to run an integrity check. You have to trust the appliance that it actually does that. And even if you get an uh resolved you can't trust that because it's running on the compromised device itself. Um, and this tool is mainly implemented through checking hashes and some sanity checks on the file system. So, it's not really a good indicator that the device is clean or compromised. Uh, and even if got that message somehow somewhere um, and it was kind of a
mind-blowing um, discovery for them that some actors actually actively manipulated the tool. Um, yeah. So there's that.