Father, Husband, Ham (AA5KS), InfoSec guy that also enjoys dirt track racing. Opinions are my own and almost certainly do not reflect those of my wife or work.
@Walkapedia_ Don’t be ridiculous, there is no value in combining natural talent with practice, training, and focused preparation. This HAS to be rigged!
@MalwareJake@anton_chuvakin Agreed. It’s not possible to be entry level in your career and be a threat hunter, but it is possible to be an entry level threat hunter,
@securityweekly It’s much worse than rm… as it’s specifically overwriting everything making recovery considerably more difficult. It’s also been around for a long time. I never knew about the status option, but used this decades ago along with a drill when a degausser wasn’t an option.
@ImposeCost It would work just as well if nerds learned non-nerd stuff. The number of tech folks that think they’re solving incredibly unique problems when they’re really only solving regular problems using overly complex technology and processes is astounding.
@BKinCT There’s a model out of… I think Drury University near Springfield, MO where they run a SOC for Small & Medium sized businesses using students. It’s a fantastic idea - first make sure they understand, then develop ML/AI to (largely) replace their initial roles.
One of the struggles in the #informationsecurity profession is that we spent years thinking we were technologists solving technology problems, when in reality we were technologists leveraging technology to manage risk that we didn’t actually understand. 1/
Now that we are coming to terms with the notion that we are actually risk managers with a deep understanding of how attackers may use technology against us, we are still viewed as the “no” people in the organization. 2/
As you interact with your information security partners (and as we interact with you) please ensure we are working together to identify the appropriate “third path” - not your preconceived notion of right, not our preconceived notion of right, but an agreeable third path. 4/
Many of us have legitimately moved on to “what is the path to yes?” This path sometimes includes helping modify the question a bit to get there - but it is a genuine objective. 3/
It’s amazing how many people think Splunk is a SIEM. If one pays for “Enterprise Security”, they have a SIEM. Without that, it _can_ be turned into a SIEM, but having an adjustable wrench isn’t the same as having a mechanic’s toolset.
It's interesting how many organizations have two SIEMs and don’t even realize it. They have Splunk but then hire an MSSP and throw everything from their Splunk, EDR, 0365, etc., into the MSSP’s ELK stack that has some fancy name 😂
Something’s broken with the current double SIEM architecture. 🧐