Let’s assume that the traditional “confusion matrix” we often use in science for measuring efficacy (TP/FP/FN/TN) is not available (and really, you shouldn’t use it). What metrics would you collect to directly or indirectly measure the efficacy and quality of your detection engineering efforts?
09.12.2024 23:10
👍 1
🔁 0
💬 0
📌 0
Expecting a tidal wave of attacks against knowledge generation.
Old playbook:
Step 1: source some overly academic prose / niche research.
Step 2: Strip any context.
Step 3: Ridicule the scholar & encourage attacks. Denounce the field.
Step 4: Call for federal funding cuts & bans.
01.12.2024 20:50
👍 91
🔁 29
💬 5
📌 4
#PIVOTcon25 #CfP is open and you can submit your proposals till 7 FEB 2025
Remember
- one track,30m
- no recording/streaming/tweeting. U should feel comfy to share more
- No TLP:WHITE
- Original content only
Let us guide u through with a little meme-thread
#CTI #ThreatIntel 1/10
27.11.2024 15:11
👍 31
🔁 18
💬 1
📌 4
Memes are now, law is later.
27.11.2024 17:40
👍 1
🔁 0
💬 0
📌 0
I’m coming for you for all my graphics needs from now on. Thanks.
26.11.2024 22:43
👍 2
🔁 0
💬 0
📌 0
Scenario: You’re airdropped into an org with tons of detection rules. What questions do you ask and why?
So far I’ve been examining source prominence, distribution of tactics (“Coverage”), and I’m working on mapping “intent” (what is the expectation of putting this signal in front of an analyst).
21.11.2024 01:24
👍 2
🔁 1
💬 4
📌 0
Those gloves came off after the demise and diaspora of Conti —which generally coincides with the war in Ukraine. We had 2ish years where healthcare targets were generally the realm of less “prolific” or capable affiliates but that era is long gone, sadly.
17.11.2024 21:34
👍 1
🔁 0
💬 0
📌 0