@GossiTheDog @da_667 most EDR products have the ability to block anything (including root/admin) from killing their processes. I'm sure there's always workarounds (that don't involve single user mode) but it'll stop things like simple kill commands. Crowdstrike has had this feature for years. And it's needed: we used to see hackers breaking in and the first thing they did was kill/remove Crowdstrike. No more...