Bobby Filar
@filar
Followers
2K
Following
11K
Media
324
Statuses
6K
dad. security machine learning @sublime_sec fmr:@elastic, @endgameinc Wizards/Timberwolves/LFC
MPLS
Joined July 2008
New @elastic blog post "Discovering anomalous patterns based on parent-child process relationships" covers a lot of material from my ProblemChild @CamlisOrg talk. https://t.co/BGJPwWTGow
elastic.co
Attackers using “living off the land” techniques can be difficult to identify. Detecting post-compromise anomalous patterns based on parent-child process relationships helps detect adversaries that...
8
80
229
New Anthropic research! We study how to train models so that high-risk capabilities live in a small, separate set of parameters, allowing clean capability removal when needed – for example in CBRN or cybersecurity domains.
33
115
1K
Excited to share we've been named to this year's #Cyber60 List, presented by @lightspeedvp, @FortuneMagazine, and @AWSstartups! It’s an honor to be included as one of the top 60 venture-backed cybersecurity companies. https://t.co/i4F3oD2TxE
0
2
10
We’re excited to announce that Sublime has raised $150M in a Series C led by @Georgian_io, joined by new investors @Avenir_Growth, @01Advisors, @jonoberheide, and @nicoleperlroth, and existing investors @IndexVentures, @IVP, @slow, and @CitiVentures. This year we launched ASA
1
7
31
Excited to share something for the football analysis community. I’ve created an open-source repository on web scraping football data from popular websites. It’s a central place to learn different scraping methods and understand how data is collected 🧵 🔗 https://t.co/rxagnzLbV3
16
53
376
This #CybersecurityAwarenessMonth, see how ADÉ helps defenders catch more threats, faster:
sublime.security
Sublime launches defensive AI agent that autonomously and continuously adapts detection coverage
0
1
3
We've seen a rash of attacks imitating online invitations (Evite, Punchbowl, etc.) to deliver a variety of payloads via the RSVP button. Multiple types of credential phishing, multiple types of RMM malware, and we assume these attacks will keep evolving. Know how to stop it:
0
3
4
Evaluating LLM Generated Detection Rules in Cybersecurity - https://t.co/Ppke986B1K This paper describes a methodology for measuring the effectiveness of LLM generated security rules, and illustrates this method using Sublime Security’s Automated Detection Engineer, ADÉ, which
0
2
9
Excited to publish this detection rule writing agent eval! Evals are critical to establish trust through transparency. Check out our paper and blog for our methodology, results, and future work. Paper: https://t.co/zN7gKOn0PS Blog:
sublime.security
A framework for evaluating the detection accuracy, robustness, and economic cost of coverage created by security LLMs
Detection teams are generally suspicious of AI security. That’s why Sublime’s ML team developed a rigorous 3-pillar framework for measuring the accuracy, robustness, and cost of LLM-written detections, so they don't just “look right,” they work. Read the blog & paper:
0
0
1
big upgrade to our natural language model!
🚀 NLU 3.0 has been deployed in the Sublime platform and is automatically available to all users – no manual updates necessary. Learn about this major model upgrade that's built for speed and accuracy in the face of rapidly evolving, AI-powered attacks and evasive edge cases:
1
3
12
🚀 NLU 3.0 has been deployed in the Sublime platform and is automatically available to all users – no manual updates necessary. Learn about this major model upgrade that's built for speed and accuracy in the face of rapidly evolving, AI-powered attacks and evasive edge cases:
0
1
10
World religions in shambles as Anthropic researchers reveal that Good and Evil are nothing more than vectors in latent space
New Anthropic research: Persona vectors. Language models sometimes go haywire and slip into weird and unsettling personas. Why? In a new paper, we find “persona vectors"—neural activity patterns controlling traits like evil, sycophancy, or hallucination.
54
153
3K
Wrote about evals at Dreadnode. This one is for hackers getting up to speed on agents for their use cases. How do you go from PoC to prod? Don't wait for a lab to build benchmarks that measure what you care about. Do it yourself. Here's how:
In our latest blog, @shncldwll breaks down the process of creating a fully integrated, self-verifying agentic system that can do modern Windows Active Directory red team operations, without human interaction. Read about our approach to building cyber evals to measure model
2
8
28
it's your FAVORITE time of the year. our annual #defcon limited edition swag drop is happening next week. here's how to get yours this year 👀 1. follow me 2. or, follow @sublime_sec drop locations will be announced throughout the days on both accounts. see you soon 🕵️♂️
4
8
22
We've had so much fun organizing a vibe coding event for kids aged 9 to 13 that we decided to show our friends how to host one too and turn it into a global event. 📆 It’s happening on October 10-11, 2025 🧑🏫 with in-person sessions hosted locally, 🌐 all connected in one giant
20
44
201
Zoom is the latest trusted service bad actors are exploiting to deliver malicious messages. In this recent attack, Zoom Events and Zoom Docs are used to deliver an adversary in the middle (AITM) credential phishing payload with a fake Microsoft login page: https://t.co/6QHtJEHdPB
0
2
3
Due to high demand, the CFP deadline for CAMLIS 2025 is extended to next Friday, July 4. Submit your full-length paper or extended abstract here: https://t.co/eSBZEquOLz. Scholarship deadline remains today! Questions? Email Program@camlis.org #CAMLIS2025
0
5
8
🚀 Exciting Announcement! 🚀 Get ready for the 18th ACM Workshop on Artificial Intelligence and Security (AISec 2025)! 📍Co-located: @acm_ccs 🗓️ Deadline: June 20th, 2025 🌐 Website: https://t.co/TGKGp4i95i w/ @ruoxijia and Matthew Jagielski
0
9
18
We’re honored to be named to @redpoint’s 2025 #InfraRed100, spotlighting the most transformative infrastructure companies! Big thanks to the team at @Redpoint congrats to our fellow innovators. → https://t.co/azrwICp9Ln
0
2
5