Stop asking LLMs to “find vulns.” Start using them to understand code.
@Sw4mp_f0x walks through using Claude Code as a force multiplier in app assessments - faster analysis, fewer false positives, better outcomes.
Check it out: https://t.co/BpMnOGBMv7
Today I'm happy to announce my newest and most ambitious project - the Azure Threat Research Matrix (ATRM). A similar look to MITRE ATT&CK Enterprise, but the ATRM will cover AzureAD and Azure resource TTPs. Official blog post: https://t.co/zbdHcyKIxH (1/2)
One of the bigger initial barriers for newer analysts to break through is understanding exactly where investigative work happens. Much of it happens in the web browser and search engine rather than the SIEM or command line. 1/
You have Multiple SIEM's, which data model did you choose and why? Every vendor has their own Data model, Splunk CIM, Microsoft ASIM, Elastic ECS, Google UDM, ArcSight CEF, QRadar LEEF, Cloud Information Model (CIM).
Anyone else see a problem here?
I usually make short-form satirical videos for fun, but never share them with the world. This time tho, I thought I'd make one for the infosec community. Some might even find it educational 😅
If you're in #infosec and you feel a little down this week, this video is for you💙
New files are being signed with the stolen #NVIDIA certificate. #Lapsus
You can search for the files signed with the stolen cert using the below query in #MDE:
DeviceFileCertificateInfo
| where CertificateSerialNumber == "43BB437D609866286DD839E1D00309F5"
#ThreatHunting#dfir
Other day I asked for large repos of detection rules here is the running list of responses.
Elastic - https://t.co/OwVwhHU3nZ
Sigma - https://t.co/LygEgGSBeB
Chronicle - https://t.co/4QqDyzJCWC
Splunk - https://t.co/csHzWFCpLE
Falcon Force -https://t.co/9cOd5elj3U
The most common action an analyst will take is performing a search. Usually in a tool like Security Onion, Splunk, Kibana, and so on. The second most common action an analyst will take is pivoting. That term gets used a lot, but what exactly does it mean? 1/
It would be awesome if Facebook released an official statement thats wildly simplistic:
“Sorry, the disk was full. Arthur deleted some old photos and it looks ok again”
💰GIVEAWAY!💰 From forensics to hunting, incident response to security ops, are you ready for our labs?
🥇= 6 Months PRO
🥈= 3 Months PRO
🥉= 1 Month PRO
1)👋 Follow Us
2)🔄 Retweet This
3)📢 Winners Announced @ Launch
#dfir#blueteam#soc#infosec#cybersecurity#labs