@kimb3r__ There's a space force (station?) near my house on the Cape I drive by every time I go to/from Boston and i'm always like 'what happens in there'
I’m going to share with you all something I shared with someone on an advisory call this week:
Stop rewarding the academic theater of PM best practices.
I’m tired of folks thinking you put insights into a magical PM framework and a great business spits out the other end.
@Andrew___Morris@kimb3r__@GreyNoiseIO What's even more interesting is these two tags which were created from Sift AI findings are related to old CVEs that aren't yet in CISA KEV
Just because the vulns are old, doesn't mean someone isn't try to exploit them!
https://t.co/J3NmRa5ks8
https://t.co/Eub2oKjv8h
🏴☠️ Registration has opened! Join us from August 7th to 14th for a virtual Capture The Flag (CTF) event, proudly featuring PCAP data captured by GreyNoise. 🏴☠️ https://t.co/QMisq6uToQ
Detection engineers, security analysts, and general security nerds: show off your skills in digging through PCAP with our special CTF challenge, culminating in a winners reveal at our Vegas party! (you can participate online-only too!)
Get glory & win [not stupid] prizes
🏴☠️ Registration has opened! Join us from August 7th to 14th for a virtual Capture The Flag (CTF) event, proudly featuring PCAP data captured by GreyNoise. 🏴☠️ https://t.co/QMisq6uToQ
Counterpoint: maybe playing MITRE ATT&CK bingo and having detections alert for every recon/initial access attempt/etc is not the best idea??
vs detect the whole attack at some point in the lifecycle
(caveat: have not read the report and not sure that is the conclusion)
Very interesting article from @DarkReading.
“…from production SIEM platforms…such as Splunk, Microsoft Sentinel, IBM QRadar, and Sumo Logic, and found that they have detections for just 24% of all MITRE ATT&CK techniques. That means that adversaries can execute about 150 different techniques that can bypass SIEM detection, while only about 50 techniques are spotted…”
It's almost that time of year! Come hang with us and see if @kimb3r__ finally pays me the $ she owes (IYKYK)! We'll be hanging out off the strip on 8/10 as well as having a (virtual) CTF going on so that folks near and far can participate! Space is limited, FTR.
@NickSDavis I'd make you contribute to it!
Honestly I'm surprised reforge or someone hasn't put it together already, what I am imagining is just basically snippets of case studies from their live courses
I really want to put a blog together that has concrete examples from real life product people on what we actually *do* and no it's not making JIRA tickets all day
Entry level PMs aren't trusted with making big investment decisions, like 'we should spend 6 months of 3 teams manpower building a new product for new market X', just like Jr Engs aren't trusted with architecting massive changes