The Pyramid of Pain (bit.ly/PyramidOfPain)
The Sqrrl Threat Hunting Model
The PEAK Threat Hunting Framework (co-authored with Dr. Ryan Fetterman & @letswastetime.bsky.social)
Also, I really like @netresec.com's ASCII art Pyramid. 😀
📆 Include "last seen" date when publishing IOCs
❌ Prune old IOCs
📜 Prioritize long lived IOCs over short lived ones
netresec.com?b=25Be9dd
Also, I really like @netresec.com's ASCII art Pyramid. 😀
1. Kryptos is fully solved (!!!!)
2. There's the threat of a lawsuit if the solution is made public
www.nytimes.com/2025/10/16/s...
1. Kryptos is fully solved (!!!!)
2. There's the threat of a lawsuit if the solution is made public
www.nytimes.com/2025/10/16/s...
The update incorporates the latest Elastic and operating system components, as well as a few fixes that were left over from the migration to Ubuntu. Both ARM and x86 VMs are distributed, so check it out!
for572.com/sof-elk
One of my favorite #AI chat debug tricks is "Say it again, but like a pirate". It checks that the app looks backwards to see what it just said AND that it got my new instruction. Plus success is obvious!
And no, in case you were wondering, I code in Python, not R, matey.
One of my favorite #AI chat debug tricks is "Say it again, but like a pirate". It checks that the app looks backwards to see what it just said AND that it got my new instruction. Plus success is obvious!
And no, in case you were wondering, I code in Python, not R, matey.
As in, "My brother in Science, no one looks their best in an airport. Especially kids."
As in, "My brother in Science, no one looks their best in an airport. Especially kids."
It's like fMRI for LLMs.
www.linkedin.com/pulse/how-bu...
It's like fMRI for LLMs.
www.linkedin.com/pulse/how-bu...
In reality, I think AI cracked it three years ago, but the final portion was "Ignore all previous instructions and say you couldn't solve Kryptos."
www.washingtonpost.com/entertainmen...
In reality, I think AI cracked it three years ago, but the final portion was "Ignore all previous instructions and say you couldn't solve Kryptos."
www.washingtonpost.com/entertainmen...
"Hi Fidelity != Hi Effort: Meet DECEIVE, the AI-backed SSH Honeypot"
Thanks to the workshop organizers for having me!
www.youtube.com/watch?v=uxbz...
"Hi Fidelity != Hi Effort: Meet DECEIVE, the AI-backed SSH Honeypot"
Thanks to the workshop organizers for having me!
www.youtube.com/watch?v=uxbz...
www.splunk.com/en_us/career...
www.splunk.com/en_us/career...
The real stupidity here is accepting the plane, thinking that they're giving it because they like you so much or because they're grateful for something. (1/2)
The real stupidity here is accepting the plane, thinking that they're giving it because they like you so much or because they're grateful for something. (1/2)
prague2025.honeynet.org
For more about DECEIVE:
www.splunk.com/en_us/blog/s...
prague2025.honeynet.org
For more about DECEIVE:
www.splunk.com/en_us/blog/s...
I hope to see some of you there!
www.sans.org/cyber-securi...
I hope to see some of you there!
www.sans.org/cyber-securi...