One of our early access customers in the financial sector made the decision to move their entire detection and response capability in-house.
The unexpected challenge wasn't building the stack.
It was validating detections, identifying telemetry gaps, and maintaining confidence in coverage as their capabilities evolved.
This case study covers the workflow they built and how they approached continuous detection validation.
https://t.co/jdsGay4p09
@IceSolst It’s primarily used to mitigate email spoofing for domains. I used to do a lot of DMARC consulting about 10 years ago, back when it wasn’t very popular where I was helping organizations move to a p=reject policy. SPF records were back then also terribly managed by most orgs…
I read @DFIRdeferred's blog on how local AI tools store secrets in plaintext. then ran AIHound and realized I'd lazily exported an Anthropic key to my shell at some point. Used the handy @1Password CLI to store it properly. Nice work by our research team! Link ⬇️
Blog showing how AI, JavaScript browser automation, and Microsoft Graph API calls can be used to automate Entra ID tenant destruction and lockout’s. Ransomware, but for Cloud? 🫣 https://t.co/TRbHIt19en