Owner of Tailwind Labs & Rudimon \\ Incident Response Lead @SnowflakeDB \\ Former Principal Consultant @paloaltontwks, Former IR Consultant @Mandiant @FireEye
Hey, last week we announced a new project called Elastic Security Labs. What is it? It's research we do which results in all the rules, signatures, etc. in @elastic security. It's over at https://t.co/qI1w3ifTPU, it's public, and I'm gonna be talking about it.
Please read this thread. This is the type of effort we need a lot more of in Infosec.
And yes, I just found out about this an hour ago, but I trust @_devonkerr_ implicitly to be a guide for bringing something like this to fruition.
Friendly reminder to my fellow detection engineers & threat intel analysts:
We (me included) often define success as generating an alert (or targeted notification) in a product - but vast majority of orgs can’t effectively investigate the alerts & respond to prevent bad outcomes