Interview with Ariel Millahuel from Buenos Aires, the active participant of Developer Program and the author of 35+ #Sigma rules. https://t.co/kaYNAWSleF #Cybersecurity@AMillahuel
https://t.co/k86H7T3FyG The only thing worse than a false sense of security is a false representation of facts. It hurts me personally, that @cyb3rops , a Sigma language co-inventor and my companion during a 6-year path of making Sigma a common language for cybersecurity, now erases my team’s legacy in it.
I just read this last evening on X:
“...The primary essence of content provided by SOCPrime and [omitted] comes from the Sigma community's rules, presented through a web GUI with some added context. It could mislead readers to believe that these content providers generate most of the content, whereas, in reality, they mostly repackage the community-driven Sigma rules. Particularly, the generic rules which are crucial, are provided by the Sigma community…” continued in Florian’s tweet https://t.co/AkDt9lPXYO
Sometimes, it takes one tweet from the company Advisor to break the trust and lose faith of people behind Sigma backends R&D, vendor alliances, threat research, community, and marketing.
Facts (The comprehensive version is in the the attached video):
SOC Prime has been the largest commercial contributor to the #Sigma language since 2017, proven by holistic effort, the number and quality of rules or even backends developed.
Our team added MITRE ATT&CK tags to Sigma rules in 2017, I publicly presented this at the very first MITRE ATT&CK EU Conference on May 24-25, 2018, which served as a pivotal event for Sigma’s popularity.
Authors who participate in SOC Prime’s Threat Bounty program, the only program to my knowledge that provides monthly payouts to threat researchers for Sigma rules, have delivered a major part of all Sigma rules created since 2017 to the date. This has set Sigma rules quantity for exponential growth.
That is without mentioning all the countless contributions, projects, educational webinars, and community efforts my team did that have propelled Sigma to its recognition and adoption today.
We believed in Sigma, due to the GPL nature of the project and DRL license, which both promote inclusivity and equal opportunity. While Sigma inventors deserve credit for the idea and initial code, the project belongs to the world and global cyber community. Popularity should not come at the expense of all of its contributors, be it backend makers, rule researchers or users who share feedback. If we are to make a difference and defend together, we need to act together. A change more significant than a pull request is needed.
@sigma_hq
Here’s my quick an dirty lab workout for Detection Engineers. I do this work out 2 to 3 times a week for about 2 hours. #CyberSecurity#infosec#BlackTechTwitter
Cisco confirms a major #hack of its IT infrastructure by #Yanluowang#ransomware gang. Detect associated malicious activity and attacker's behavior patterns with a dedicated pack of #Sigma rules in the SOC Prime Platform.
https://t.co/5jlpX4d0qB
#DFIR#BlueTeam#ThreatHunting
Do you think an effective #cybersecurity strategy requires a fortune? Learn how to optimize your budget and resources to make the most out of it in our new guide for #SMBs on Medium! https://t.co/1NGRG9If14 #cyberdefense#threatdetection#BlueTeam
I wrote this SIGMA rule writing guide.
It focuses on defining the critical components (logsource & detection) and includes some of my thoughts on detection engineering in general.
SOC Prime is thrilled to announce that Uncoder CTI is now available for public use — at no charge and without registration via https://t.co/lFf5RIJ9MM. Boost your #threathunting with instant generation of custom IOC queries ready to run in your #SIEM & #XDR.
Check out the reveal of @AMillahuel's new resource! Great stuff from one of @SOC_Prime's own! Threat Hunting from Zero to Hero - P.1 https://t.co/b0vTSZ1wdt via @AMillahuel
Hello twitter! I'm looking for an engineering leader to join my organization here at Netflix, leading a team of incredible high caliber engineers building IAM systems & services. The role is open to remote candidates in the US. Applications welcome here: https://t.co/9XI8YY2v6y
I want to thank every one of 600+ members of our community who downloaded #zerologon detection for sharing feedback to us! You rock! #sigma translations are getting updates today + guidance on how to detect the attack with Zeek and EventLog. Stay tuned.
#DFIR CVE-2020-1472