🚨EDR telemetry evals for the new Linux category have started. The first results are in, and they ain't pretty 😔
I genuinely hope vendors succeed because it benefits everyone! Even so, the telemetry evals will remain objective and open to improvement via community feedback. We have just started tho; there is a lot of work ahead.
*PS. Don't ask if I will include XX vendor. We will first try to cover the ones that we currently have over on the Windows side.
** I won't disclose which vendors are next to Sysmon in that screenshot. We want to ensure that the process undergoes a proper community review before release.
EDR Telem issue for reference: https://t.co/3XG5OP7to2
How System Calls Works: Understand Standard C Library Invoking
The user application program first configures the system call's arguments. Then, it executes the "system call" instruction, which results in an exception—an occurrence that jumps the processor to a new address and begins running the code there.
The instructions at the new address save your user program's state, determine the system call you want, call the kernel function that implements that system call, restore your user program state, and give the user program control again.
You can read more here: https://t.co/Lix57v96lS
GitHub Repo [OS Book]: https://t.co/fvmn7Mt3dQ
This was a very quick and concise overview of system calls; I will go into greater detail about this in my OS book mentioned above.
The Linux Storage Stack Diagram
I will try to write a detailed article explaining all this and the connection as this is too cool to just stay as a picture.
The Emergent Abilities of LLMs Could Be A Mirage!
The best paper award in NeurIPs 2023 went to a paper claiming that the emergent abilities of LLMs could be a mirage!
The paper (link in alt) asserts that emergent abilities appear due to the researcher’s choice of metric rather than fundamental changes in model behavior with scale.
Let's understand some terms before getting into the details.
Emergence is a phenomenon whereby new properties may materialize in systems as their complexity increases. These properties can't be predicted from a precise quantitative understanding of the system’s microscopic details.
Emergent properties of LLMs are abilities that are not present in small models that manifest themselves in larger models (Sharpness), and their performance on specific tasks can emerge quite unpredictably and abruptly at scale (Unpredictability)
A lot of drama around LLMs taking over the planet involves emergence. Researchers argue that some scary emergent properties like free will and consciousness can magically manifest themselves in LLMS, and therefore, we have to pause, ban, and regulate AI research.
The paper excellently and credibly argues that the LLMs DO NOT possess emergent abilities - by this, they mean that there isn't anything sharp or unpredictable about them.
They show that smooth, continuous, predictable changes in model family performance appear sharp and unpredictable based on the choice of metric. So bigger models naturally and smoothly are more performant; there isn't some sharp jump in performance.
They also find that for non-linear metrics, smaller models are more performant than previously reported when they add additional test points to increase the resolution of the benchmark.
Overall, the point of the paper is that LLM behavior is NOT unpredictable, and in fact, larger LLMS are predictably more performant than larger ones.
In other words, there is no scientific reason to believe that LLMs can magically become supervillains one day.
If there is one paper you should read about LLMs, I recommend this one!
TLDR: There is no magic voodoo happening with LLMs; it's all math and statistics... as all deep learning is
Today marks the 75th anniversary of the transistor—a basic building block of modern electronics, and one of the key inventions of the 20th century. Take a closer look at this tiny semiconducting marvel + its predecessor, the vacuum tube, in Open Circuits: https://t.co/ie5zJKXMbb
The single biggest argument about statistics: is probability frequentist or Bayesian?
It's both, and I'll explain why.
Buckle up. Deep-dive thread below.
The #sysmon-modular project has been expanded. Most importantly with an #MDE augmentation config. This config will only generate the event types where MDE falls short.
I'll write a blog soon to explain the nuances and considerations to enrich it yourself.
https://t.co/WAf5jx69Hx
How to prevent Kerberoasting:
Kerberoasting is an incredibly powerful and reliable attack against Active Directory. In some situations it can result in an attacker becoming Domain Admin nearly instantaneously.
Here's how to prevent this attack: 🧵
If you are at @BSidesLV you can’t miss at 14:00 our own @zkvL_ from @bishopfox who will be giving a 101 talk on ICS security assessments https://t.co/9J2oFUev48
A Blue Whale was spotted off the coast of Vancouver Island yesterday. The largest animal to ever grace this planet. The largest dinosaur weighed around 85 tons. Some male Blue Whales weigh as much as 200 tons. A Blue Whale's heart is 6 feet wide and weighs 400 lbs.