🤖 The advent of AI in cybersecurity:
A few organizations & security firms play chess; most play checkers.
As AI evolves, all must master chess or risk being outmaneuvered.
Some people think being technical is a detriment to being CISO.
🤡 Don’t be a haha-CISO.
Don’t listen to articles telling you what you should be.
Yes, you need to have business skills but I’ll take a CISO who knows attackers and tech over one who has no idea, any day.
Security programs measured by risk alone, or by compliance, or by bowing to the business in every situation often fail.
They often waste money on imaginary metrics of their own devising. They often prioritize programs poorly. They exist to perpetuate themselves rather than answer important questions.
Interviewer: "I heard you were extremely quick at math"
Me: "yes, as a matter of fact I am"
Interviewer: "Whats 14x27"
Me: "49"
Interviewer: "that's not even close"
me: "yeah, but it was fast"
Awesome reverse engineering blog post about @Tesla Model 3 internals by @rice_fry:
"Hacking my Tesla Model 3 - Security Overview":
https://t.co/XpjX7FKYG1
Another long (hacker) story thread 🧵
= Stealing checks worth millions & pwning a bank =
Here’s how I did it, so you can learn.
I was once contracted to do a penetration test on a bank…
Like, retweet, and follow for more hacker stories!
(1/x)
It's time to look beyond Offensive Security in this industry. Training diversity matters when building diverse teams, and that applies to any field.
If you're a hiring manager, take note of some of these alternatives you may see on resumes and accept them. A thread 🧵
Other day I asked for large repos of detection rules here is the running list of responses.
Elastic - https://t.co/OwVwhHU3nZ
Sigma - https://t.co/LygEgGSBeB
Chronicle - https://t.co/4QqDyzJCWC
Splunk - https://t.co/csHzWFCpLE
Falcon Force -https://t.co/9cOd5elj3U