Since Solarwinds Hack and Hafnium attack involved some degree of unauthorized code modification (orion DLL, creation of web shell), is it possible to use Artificial Intelligence (AI) built into the very application (Solarwinds, Exchange Server) itself to detect and report any unauthorized code modification and unnatural modification its immediate environment (e.g., processes supporting the application, or detection of files such as exfiltrated files that should not be there, in the application binaries folders)?
It is my firm belief that building AI into these application is the only way forward to reduce/stop zero-day exploits.