@juanandres_gs From a student: Would you say this dilution effect has impacted the paywalled reports as well, or have they gotten better? Has the "relentless mess of daily operational tasks" really increased that much? Are there silver linings to these shifts, or is it all unfavorable?
@jamieantisocial Wow this seems like a really advanced report, but that's also due to me not being super experienced. Curious where this lands detail-wise on reports you are usually looking through and if you have a process for reading these (or do you simply read/ skim top-to-bottom)?
@mattjay So, if I'm understanding it correctly, ShinyHunters were able to compromise an OAuth token using the LummaStealer malware, which then allowed them to pivot to Vercel's environment because of the Allow All permissions set in place? How did they pivot to accessing the EVs?
@fr0gger_ When it comes to the Pyramid of Pain, where do IoPCs land? How are these prompts detected in a way where they aren't like hashes that can be easily modified? I'm assuming this has to do with the semantic detection in the NOVA rule framework, but would love an explanation on this!
@magicswordio I get why vendors would be incentivized to keep the "detection cycle" going, but why would they willingly do that for their own company when they could implement your solutions and reduce the flow of alerts? Maybe I'm missing something here, but my point is the problem is deeper
@magicswordio I like the takes in this article, but want to push back against something. The claim that companies are neglecting prevention because "detection engineering is a business model" makes it sound like the security teams are purposefully leaving themselves open to attacks. Thoughts?
@fr0gger_ Curious if you've taken a look at this technical report yet. It reminded me of your work related to IoPC since there were logs of the actor's prompts in the report. Crazy real world impact as well!
Chat, I've changed my mind. We have some problems in the AI department.
It turns out someone compromised the Mexican government to an unbelievable extent using nothing but Claude and ChatGPT. I'll link the full paper in the subsequent post. However, here is the highlights of how
@ipurple@M_haggis Is it that the organization's aren't using enough rules to cover these procedures or that the rules aren't specific enough in the first place? I understand the MCP server is useful for searching through existing rules for varying use cases, but still confused about this
@M_haggis In your opinion, how effective are these rules at actually detecting threats? I've recently gotten into detection engineering and was testing out Sigma rules against the acme4 dataset , but it seemed like the rules were completely overlooking the malicious traffic
2K Followers 2 FollowingNew streams every Friday! All channel proceeds go back to the community! Check out https://t.co/um6KVfwMFJ for our AI-powered offensive security testing platform!
111K Followers 104 FollowingThe world's leading Digital Forensics and Incident Response provider. This feed updates you on latest DFIR news, events, and training.
30K Followers 205 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
69K Followers 81 FollowingThe latest research and news from Unit 42, the Palo Alto Networks (@paloaltontwks) Threat Intelligence and Security Consulting Team covering incident response.
67K Followers 997 FollowingU.S. @ENERGY and @NNSAnews laboratory. We use science and technology to make the world a safer place. Verification: https://t.co/29pFxbpHmQ
30K Followers 1K Following24/7/365 threat detection and response across your cloud, identity, endpoints and everything in-between. We got you: https://t.co/3tlcMwxXMa
2K Followers 1 FollowingTrain on raw telemetry from actual breaches. Investigate malware and reconstruct the kill chain from process creation to exfiltration and beyond.
20K Followers 527 FollowingPrivate, secure and decentralized messaging. The first network where you own your contacts and groups. Get the open-source app: https://t.co/7cmX6RYaiq
38K Followers 260 FollowingWe help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
68K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD