Security is like retirement:
- you need to be investing monthly,
- the best time to start investing is now,
- investments bear compound interest over time,
- the effectiveness of “catch up contributions” is limited
Once you have seen which events are delivered in #ETW channels, the events from the normal event logs will never be enough, no matter how verbose the audit policy is set
📢The Microsoft AI Red Team is hiring across all levels!
Your area can be Adversarial ML or Responsible AI or Pen testing, and you will fit right in!
Questions? DM always open
Junior: https://t.co/LhUulLU27C
Senior: https://t.co/2wSxoQiBuu
Principal: https://t.co/6NkKUkVPzX
@HackingLZ Would the dynamics change if red didn’t have to spend time gaining an initial foothold?
Unless the focus is explicitly on finding new ways in, I’m a big fan of giving red an implant in whatever system they want and letting them go from there.
@JohnLaTwC@royalhansen John and I kept an eye out for Yamadori bonsai on the trail — this one is clearly too big but the natural twist is kind of fascinating. No idea how this happens in nature!
Today @MSwannMSFT and I completed our hike of a section of the Pacific Crest Trail. Huge thanks to @ram_ssk for giving us a lift to the trailhead. Here is what we experienced 👇
1/ A few weeks ago I gave a talk about how Security Fundamentals functions across the OneDrive + SharePoint organization. A short thread 🧵 on how we framed this topic and what we believe success looks like in our engineering organization:
@SwiftOnSecurity@philvenables The final thing I’d leave you with: detection is a compensating control. “Compensating” implies that it’s in lieu of something better!
Don’t settle for a highly-monitored environment full of risk. DO detect a cut finger in milliseconds, but also - remove the sharp edges!
@SwiftOnSecurity I have lots to say about controls, but @philvenables has covered it in great deal. This is a fabulous place to start: https://t.co/XInWt6waRQ