惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
D
DataBreaches.Net
博客园 - 三生石上(FineUI控件)
H
Hacker News: Front Page
Know Your Adversary
Know Your Adversary
Recorded Future
Recorded Future
The Hacker News
The Hacker News
Help Net Security
Help Net Security
月光博客
月光博客
L
LINUX DO - 热门话题
Hacker News - Newest:
Hacker News - Newest: "LLM"
T
Tor Project blog
Security Archives - TechRepublic
Security Archives - TechRepublic
aimingoo的专栏
aimingoo的专栏
Attack and Defense Labs
Attack and Defense Labs
Project Zero
Project Zero
V
Vulnerabilities – Threatpost
SecWiki News
SecWiki News
S
Security @ Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
V2EX - 技术
V2EX - 技术
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
A
Arctic Wolf
T
Threat Research - Cisco Blogs
WordPress大学
WordPress大学
H
Heimdal Security Blog
小众软件
小众软件
C
Check Point Blog
T
Tailwind CSS Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
C
Cyber Attacks, Cyber Crime and Cyber Security
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
L
LangChain Blog
博客园 - Franky
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
J
Java Code Geeks
Apple Machine Learning Research
Apple Machine Learning Research
C
Cybersecurity and Infrastructure Security Agency CISA
C
CXSECURITY Database RSS Feed - CXSecurity.com
Microsoft Security Blog
Microsoft Security Blog
Google DeepMind News
Google DeepMind News
有赞技术团队
有赞技术团队
MyScale Blog
MyScale Blog
S
Schneier on Security

HBR.org

How People Actually Get to the C-Suite in S&P 500 Companies Our Favorite Management Tips on Giving Feedback The Case for Hiring a Chief Resilience Officer What Customer Workarounds Can Reveal About Your Business Model Getting Buy-In for Your Next Big Idea Surprising Ways to Reduce Turnover in High-Pressure, High-Skill Jobs “Listen for the Silence”: Insights from a Long-Serving CEO Supporting Your Employees’ Career Growth When Everyone Is Overwhelmed What Really Gets in the Way of Change How Stronger Privacy Laws Convinced Consumers to Share More Data How to Break Free of Negative Thought Spirals A Breakthrough Board Presentation Can Win You the CEO Job The Keys to Succeeding Under a New Manager Do You Recognize Burnout in Your Organization? Should Your Subscription Business Use Auto-Renew? Gen AI Could Fix Performance Reviews—or Make Them Even Worse What Operating Rooms Can Teach Leaders About Team Design What Global Companies Lose When Decision-Making Revolves Around Headquarters Redefining What Efficiency Means in the Age of AI It’s Hard to Use AI as a Team. These 3 Practices Can Help. Are You Meeting the Needs of the People You Lead? Beware the Agentic Convergence Trap Should You Treat AI Like a Teammate? Research: Traditional Marketing Doesn’t Work on AI Shopping Agents The Leadership Skills That Make Transformation Stick Microsoft’s Path to Adopting and Scaling AI Across its Sales Organization Why Leaders Should Let Minor Mistakes Slide What Are Your Company’s AI Nightmares? “Cyber Defense Has to Move at the Speed of AI” How Fast-Growing Companies Can Make Better Decisions Redesigning Your Marketing Organization for the Agentic Age Why Effective Leaders Get Branded as Problems 3 Ways AI Can Free Organizations from Legacy Workflows Communicating with Confidence When You’re Under Pressure How Sales Teams Undercut Themselves with Longtime Clients Research: Why You Shouldn’t Treat AI Agents Like Employees Why Professional Services Organizations Keep Solving the Wrong AI Problem - SPONSOR CONTENT FROM CERTINIA When an Executive Asks You an Unexpected Question New Skills to Navigate Continuous Change The Best Leaders Embrace the Role of Supporting Character How an Organizational Shift Can Unlock Real Value from a Stalled AI Strategy - SPONSOR CONTENT FROM PUBLICIS SAPIENT How AI Is Changing the Needs and Values of Finance Leaders and Their Teams - SPONSOR CONTENT FROM DELOITTE Stop Trying to Replicate a Single Star Performer Will Insurance Protect Your Company in Times of War? The Art of Discounting How Executives Should Deal with Heightened Security Risk Research: For Women on Boards, Prestige Can Be a Bottleneck The Psychological Costs of Adopting AI How to Move from AI Experimentation to AI Transformation Empathetic Leadership Can Make or Break AI Adoption Driving Lyft into the Future Accountability Must Be Chosen, Not Mandated How to Nail Your Next Media Interview Build Your Resilience in the Face of Tough Change U.S. Medical Centers Need a New Model for Drug Discovery and Development Why Your Team Won’t Speak Up (And How to Fix It) Where the U.S.’s Chip Strategy Is Still Falling Short How a Family-Owned Greek Cement Company Evolved Its Leadership While Pivoting Its Product Portfolio How the Walkman, Game Boy, Liquid Death, and Pokémon Became Surprise Hits The Future Is Shrouded in an AI Fog How to Succeed Like Apple’s Tim Cook Research Roundup: A Surprising Benefit of Upskilling, Why Goals Can Backfire, and More The End of One-Size-Fits-All Enterprise Software Making the Shift from Individual Contributor to Leader What Values Do You Really Stand For? The Comeback of the Physical Store—and What It Means for Your Business The HBR Guide to CEO Transitions Research: When Corporate LGBTQ+ Allyship Only Happens in June What Sets Superteams Apart from the Rest When the CEO Becomes the Brand When Apologizing to Customers Hurts More Than It Helps Leaders, Treat Resistance to Change as Valuable Data The AI Leadership Imperative Research: What China’s AI Agents Reveal About the Future of Commerce 5 Questions Leaders Should Ask Before Turning to Fractional Work When Your Ambition Starts to Exhaust You Scaling a Business Beyond the Family Playbook Why Leaders Need “Power Skills” Should You Develop Your Leadership Strengths—or Fix Your Weaknesses? Tapping Talent from a Skilled Labor Pool That Supports Global Ambitions - SPONSOR CONTENT FROM INVEST NORTHERN IRELAND Our Favorite Management Tips on Organizational Change To Gain Customer—and Employee—Loyalty, Go Beyond Good Enough The Hidden Demand for AI Inside Your Company The Challenges of Scaling a Technology for Social Good How AI Is Threatening Platforms’ Revenue Streams In Winner-Take-All Markets, Diversification Is a Liability Limiting Your Exposure to the Private Credit Crisis  How to Convince Your Boss They Need a Coach When You Start to Find Employee Requests Irritating What’s Stopping the 4-Day Workweek? What the Best Private Equity-Backed CEOs Do Differently Is Your Company Suffering from Initiative Overload? How Integrated Wearable Technologies Are Shaping the Next Era of Health Care Innovation - SPONSOR CONTENT FROM MEDTRONIC What AI Can’t Do: The New Job of Leadership New Research on How Brand Associations Drive Customer Spending Managers and Executives Disagree on AI—and It’s Costing Companies A New Model to Drive Financial Health and Commercial Sustainability in the Development Sector - SPONSOR CONTENT FROM MASTERCARD AI Is Reshaping Cyber Risk. Boards Need to Manage the Threat. Decision-Making by Consensus Doesn’t Work in the AI Era The Case for Designing Work Around Circadian Rhythms
Video Quick Take: How Small Pieces of Code Can Defend an Entire Operating System - SPONSOR CONTENT FROM THREATLOCKER
2026-06-19 · via HBR.org

Julie Devoll, HBR

Hello, my name is Julie Devoll, editor of special projects and webinars at Harvard Business Review. I recently had the pleasure of attending Zero Trust World and sitting down with ThreatLocker senior software engineer Farid Mustafayev. Farid explained how carefully designed Windows components can influence and protect operating system behavior and why defensive architecture begins with disciplined code.

Farid, thank you so much for joining us today.

Farid Mustafayev, Threatlocker

Thank you for having me here.

Julie Devoll, HBR

So, from an engineer’s perspective, how can a relatively small application influence and protect behavior across an entire operating system?

Farid Mustafayev, Threatlocker

The point is the operating system is centralized enforcement end points. And if [an] attacker put his code on that level, in that case, he can change the behavior of the application. Just think about that.

First of all, kit process—that’s the level of the kernel. And if someone intercepts that level, in that case, he can change the behavior. For example, filter drivers that we are putting there as well—so ThreatLocker [is] using [a] filter driver for that. And that way we can handle every single application [that] goes through the system on that level.

Julie Devoll, HBR

So what are the biggest technical challenges, then, when building security controls that operate at the system level rather than at the application level?

Farid Mustafayev, Threatlocker

The biggest technical challenges here can be multiple. First of all, it is safety, safety of the running application, because every single small developer issue on [the] system level can crash the whole system. And the point is, when [a] developer implements that, it is not obvious for every single system, because every single system, depending on the patch version that it has, depending on the operating system version, can behave differently.

\And that way, a developer should be really careful about every single small change. And also the performance—the performance itself is very important. Usually, we are spending a lot of hours trying to make performance better and better, because every time, when every single file application—for example, let’s say by the filter driver intercepted, even [a] milliseconds delay can have very big consequences.

Just imagine, like, during one hour, [a] system handles more than 1,000 or 10,000 applications. And if we have [a] filter driver [that] intercepts all of them, in that case, it takes a lot of time to handle every single one. That way, developers are trying to find some good approaches with caching and on different levels to not block operations and just let them go through.

Julie Devoll, HBR

So in a world where attackers are constantly evolving their techniques, how do engineers design controls that remain effective without [being in] constant reactive mode?

Farid Mustafayev, Threatlocker

Yeah, the point is, in [the] modern world, there is no reason to try to find every single application [that] can be malicious. That signature approach, which usually [an] antivirus is using, is not really good for [the] modern world, because everything changes so fast.

And I would say the modern security companies trying to go either with [a] behavior-based approach or going to with allow listing, default deny, as we say in [the] ThreatLocker approach. And that way, it doesn’t matter what kind of techniques are going to find attackers. We are going to intercept it. We are going to find—we are going to block the application. And that way, technique doesn’t really matter to us.

Julie Devoll, HBR

Well, Farid, thank you so much for sharing your insights with us today.

Farid Mustafayev, Threatlocker

Thank you.


Click here to learn more about Threatlocker.