Ah, this is a good point. Indeed, we don’t “detect intent” but to detect a threat in “connection to port 443” you need to look at context and then judge intent. SO, yes, my language was a bit sloppy since we don’t really detect intent…
Originally published at Medium.