It's my birthday and I have one Twitter request:
Please tell me about the diversity and #womanintech organizations you know about. I want to understand what organizations are out there, how they operate, and how I can engage.
#wisp#diversity#DiversityandInclusion
Congrats to my close friend for releasing "LOLDrivers" to the world! A fantastic list of Windows drivers that adversaries use to slip past defensives. Kudos for helping us all fight the good fight! 🎉💪 #CyberSecurity#LOLDrivers
Introducing the Living Off The Land Drivers (LOLDrivers) project, a crucial resource that consolidates vulnerable and malicious drivers in one place to streamline research and analysis.
https://t.co/hORF6hMqEr
LOLDrivers enhances awareness of driver-related security risks and empowers organizations to mitigate these risks, improving their overall cybersecurity posture. By fostering collaboration and knowledge sharing within the cybersecurity community, LOLDrivers, along with sister projects like LOLBAS and GTFOBins, paves the way for a safer and more secure digital landscape.
Read our release blog to learn all about the project and how to contribute
https://t.co/Fl2ywkXNuM
Huge shoutouts to @_josehelps , @bohops , @nas_bench , @cyb3rops and @mattnotmax for their invaluable contributions and unwavering support in bringing the LOLDrivers project to fruition. As we celebrate this milestone, we now invite the broader cybersecurity community to join us in this endeavor. Together, we can continue to enhance the project and share knowledge. Thank you once again to our amazing team, and let's keep the momentum going!
What types of questions would you ask if you were sitting on a repository of every executable that had ever existed within your organization for the last year? You have the full file contents and it doesn't even matter if the file is on disk anymore. #DFIR#ThreatHunting
https://t.co/zeBxf1nod6 update: Now that we’ve closed our Series A we’re completely gutting the GreyNoise backend, completely rearchitecting, and rewriting most components from scratch.
If y’all think GreyNoise is cool now, your minds are going to fcking shredded in six months.
@plugxor@BakedSec +1 on hypotheses and processes. Meaningful discovery is often the byproduct of well-formed questioning.
FWIW, I think we have less of a questioning problem in security, and more of a data and interrogating said data scale problem.
@SecurePeacock Good perspective! I have security management friends who are responsible for training. It's a pretty trivial cost for them to pay for something like Pluralsight licenses, which is entirely different, of course. But the cost of SANS is too expensive - does a middle ground exist?
@CD_R0M_ You bring up an excellent point. I wonder if it's worth it even as a security manager who is responsible for the training budget. I have some friends in such roles and they're having a hard time justifying the cost.
@_chrisabbey Good call, Chris! Work study computes to like an 85% savings, right? What's the process to apply and what does SANS look for in applicants?
Just wrapped up my first 30 days at @InsideStairwell. What a journey! I feel lucky to work with a tight knit of insanely passionate people who are obsessed over solving interesting security problems.