Cyb3rDefender Profile Banner
Trevor Miller Profile
Trevor Miller

@Cyb3rDefender

Followers
1K
Following
870
Media
38
Statuses
206

Manager - CTI & Detection Engineering | Tech Nerd 🤓 | Learning Addict | Dedicated to defensive #Cybersecurity

San Diego, CA
Joined August 2015
Don't wanna be here? Send us removal request.
@Cyb3rDefender
Trevor Miller
28 days
Appears using DNS-over-TLS on android "Private DNS" with a "custom provider" to sinkhole DNS requests for trackers and Ads puts a warning that the country may not be accurate because your using a proxy or VPN... Which is misleading, but I like the spirit of this move by X.
0
0
1
@AmitaiCo
Amitai Cohen 🎗️🤟
2 years
Every CTI analyst worth their salt has summited the venerable Pyramid of Pain, but I think it's time for a few other threat detection metrics to get their own monuments. Here are a few candidates for your consideration:
8
29
121
@Cyb3rDefender
Trevor Miller
2 years
📢Introducing stutterAI: Unleash the power of AI in your terminal! ⭐Fix command errors with a single command. ⭐Generate commands from a description. I Need some beta testers! https://t.co/4shWw6ACoC
github.com
Your AI assistant in the terminal. Contribute to CyberDefend3r/stutterAI development by creating an account on GitHub.
0
0
3
@Cyb3rDefender
Trevor Miller
2 years
Interesting Take. https://t.co/Ebt4BYtMfo
0
0
1
@Cyb3rDefender
Trevor Miller
2 years
This is a cool #Python project! The only thing is that when exporting the #MITRE #ATTACK layer to SVG, the Tactic row has no background; I think I identified why. Posting for attention in case someone smarter than me has time to check it out. https://t.co/5ZVGeNFId4
0
1
3
@Cyb3rDefender
Trevor Miller
3 years
@mslopatto I got Bard to reason its way to answering the question correctly. I know that isn't the point of your article, but I found it interesting. Side note, Bard seems to struggle with using previous responses containing code snippets as context.
0
0
1
@Cyb3rDefender
Trevor Miller
3 years
#Bing actually did the best job. On follow-up questions, #GoogleBard gave some nonsense KQL queries where Bing was pretty much spot on.
0
0
2
@Cyb3rDefender
Trevor Miller
3 years
I got access to #GoogleBard this morning and asked about CVE-2023-23397, and it was helpful, not perfect, unlike #ChatGPT which had no idea what I was talking about. However, I think #Bing did a good job too.
4
2
7
@Cyb3rDefender
Trevor Miller
3 years
Our analysts document all investigations in our SOAR. It is common for them to look up past incidents to see how others have done previous investigations if they need guidance. As well as being able to leverage lessons learned from incidents across our client base.
0
1
2
@Cyb3rDefender
Trevor Miller
3 years
As a vendor-agnostic MSSP, it is a little hard to be more specific as clients leverage different technologies with varying capabilities and log sources.
1
0
2
@Cyb3rDefender
Trevor Miller
3 years
We do provide investigation guides with semi-generic steps for an investigation or at least a place to start one. We have an entire wiki built around our detection library for our analysts. I wouldn't call it a playbook but more of a launching point.
2
0
2
@Cyb3rDefender
Trevor Miller
3 years
This tweet stemmed from a client asking to see our playbooks for every detection. When we said we don't do that, they said, "how do all of your analysts do the same level of investigation if they don't have clearly defined steps to follow?"
1
0
1
@Cyb3rDefender
Trevor Miller
3 years
What is your opinion on per-detection playbooks for analysts? I see pros and cons. Playbooks may lead to rigid investigations that miss malicious behavior, as one can't predict all procedures used by threat actors. Though I do see a case for repeatable steps to follow...
16
14
37
@Cyb3rDefender
Trevor Miller
3 years
Wrote a new rule today... Everywhere I possibly could, in the justification, description, logic, etc., I put *regsvr32* when I meant *rundll32*. Peer review can't catch a mistake if it doesn't look like one...
0
2
12
@Cyb3rDefender
Trevor Miller
3 years
The idea behind @echotrailco is pretty cool, but their free tier is way too restrictive to be able to assess its benefits in a meaningful way. https://t.co/j1eleytspa
0
0
1
@Cyb3rDefender
Trevor Miller
3 years
I dug up an old script for a project today... I'm glad #Symantec hadn't changed the API, it saved me so much time! Simple script to search Symantec EDR and download matching events using a single command. https://t.co/bpAS9cj5Ov
github.com
Script used to pull logs from the Symantec ATP console using the API. - CyberDefend3r/Symantec-ATP-Events
1
2
8
@Cyb3rDefender
Trevor Miller
3 years
Greater Visibility Through PowerShell Logging https://t.co/y2Qud5XYpd
2
3
14
@Cyb3rDefender
Trevor Miller
3 years
#notion is 🔥
4
0
15
@Cyb3rDefender
Trevor Miller
3 years
The day I fell in love with #CyberSecurity was when I was 12, and I got a virus ⚠️ on my first computer from downloading music on Kazaa. I had to know how it worked, and it was all downhill from there. 🤣 Pretty much this 👇 https://t.co/ySQ5j6Yzlh
0
0
5