Detection Lead @ Mandiant Managed Defense / Former IR Consultant @mandiant. Tier 3 Hipster; I came in like a #WrectorBall San Francisco, CAJoined July 2012
I don't feel like this is the right question. Threat hunting is a function of detection engineering, where detections are being tested and matched against customer telemetry. If not matches, no additional work. The question we should be asking is what is the service hunting for?
I don't feel like this is the right question. Threat hunting is a function of detection engineering, where detections are being tested and matched against customer telemetry. If not matches, no additional work. The question we should be asking is what is the service hunting for?
Question for Threat Intelligence Analysts, and SOC alike... would you consider Detection Rules Threat Intel?
Curious on the perspective of consumers of DE content whether or not Detection Rules should be considered Threat Intelligence or not.
Strong agreement here. Detection Engineering is an exercise in labeling and classifying security relevant data.
FP reduction is critically important in reducing alert fatigue, but the opportunity to tune comes directly from SOC dispositions. It's the best feedback loop you have
If you're in the Detection Engineering space, come watch @FryGuy2600 and I geek out on all things DE. We have the following planned:
1️⃣ Establish what DE is and isn't
2️⃣ Details on the DE process from a practitioners perspective
3️⃣ DE Maturity model
4️⃣ Measuring success
🎯🎯🎯
If you're in the Detection Engineering space, come watch @FryGuy2600 and I geek out on all things DE. We have the following planned:
1️⃣ Establish what DE is and isn't
2️⃣ Details on the DE process from a practitioners perspective
3️⃣ DE Maturity model
4️⃣ Measuring success
🎯🎯🎯
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
223K Followers 6K FollowingFounder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
36K Followers 7K FollowingWeird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
120 Followers 2K FollowingSwing trading for a living 💻 Analyzing charts and market data 📊 Sharing technical analysis and trading insights 📉 Learning from successful traders
408 Followers 955 Followingintel nerd & admitted tech idiot. tier 6 memes only.
rambles about security and stuff.
ridin w/ no tint so mf-ers know it's me.
army vet. human rights ally.
1K Followers 975 FollowingICS/embedded and cybersecurity researcher, water sports fanatic, chihuahua owner, maintainer of things, and sharer of knowledge.
39K Followers 1K FollowingHead of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer.
Former @USMC.
223K Followers 6K FollowingFounder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
38K Followers 3K FollowingTech Director / Threat Intelligence at Microsoft. Previously, Director of Incident Response & Intel Research at Mandiant. Former Chief Technical Analyst at CISA
55K Followers 3K FollowingDirector of Intel at @redcanary. SANS Certified Instructor for FOR578: CTI. Senior Fellow at @CyberStatecraft. She/her. Mastodon: @[email protected]
32K Followers 2K FollowingTV Host. Travel Writer. Former Mayoral Candidate. Top 20 accounts in SF (Buzzfeed)
Best email list ever: https://t.co/I4thf8Zrhg
(He/Him)
967 Followers 4K Following@googlecloud Threat Intel Comms Lead. I don't want to sell anything, buy anything, or process anything as a career. @markkarayan.bsky.social
635 Followers 164 FollowingFrom Market to Cesar Chavez, bursting with @SharedSpacesSF flavor & fun, longing to shed motor vehicles and become “Valencia For The People” 📷 @irapolis
1.4M Followers 958 FollowingMenswear writer. Editor at @putthison. Creator of @RLGoesHard. Bylines at The New York Times, The Financial Times, Politico, Esquire, and Mr. Porter
10K Followers 6K Following@Volatility Core Dev | Art of Memory Forensics co-author | Director of Adversary Tactics @HuntressLabs | #DFIR enthusiast/trainer | [email protected]
36K Followers 7K FollowingWeird security voyeur. Vibe merchant. CISO of your 🩷 Official USPS fan account. 🎉 Host of THE Microsoft Threat Intelligence Podcast. I like crime actors.
42K Followers 2K Following#infosec engineer | all things gaming | void hunter | will shitpost | i like to lift weights & play piano | los angeleno currently in twin cities | fight on✌️
10K Followers 377 Following“The One Woman Purple Team” Sr Sec Eng @ Aquia. Host of @TheCyberQueens Podcast. For help breaking in to #cybersecurity see @FearlessSec and @Maekshyft.
797 Followers 674 FollowingExtremely Hardcore full spectrum middle manager. ex red team, blue team @ Pinterest, Dropbox , Facebook, Yahoo!, etc⚡️⚔️🛡🗝🤫 Knows Mike Schwartz.
245 Followers 879 FollowingCISSP, ISSAP, CCSP | Kempo Black Belt | MM | Wanderer
Personal account. I speak only for myself. IMHO. IANAL. Assume positive intent.
15 Followers 133 FollowingDabbles in stuff | all things malware & intel, detections, programming, lots of sporty things | #threatintel @PwC | All views my own.
841 Followers 52 FollowingSr PM Google Cloud Security, co-host @cloudsecpodcast. Reducing info risk, increasing physical risk w/ motorcycles and skis. It should just work. (he/him)🏳️🌈
5K Followers 4K FollowingVirtual Routes tackles the impact of digital and emerging technologies on global affairs. Also check out @bindinghook, our media outlet.