Phil Neray
@rdecker99
Followers
446
Following
447
Media
158
Statuses
438
Cyber. Motorcycles. Cars. Jiu-Jitsu.
Joined March 2009
Alejandro Mayorkas, Secretary of the US Department of Homeland Security: “We need you [the hacker community].” #defcon31 @AliMayorkas
0
0
0
On May 19, 1998 seven intrepid hackers from Boston drove a Ford Econoline van down Route 95 to Washington DC to offer testimony to the Senate Government Affairs committee on the state of computer security in government. Their voices still echo across the Internet today.
23
215
1K
A good attack technique is to blend in with infosec noise and look like a false positive. It will give your attack a greater window of opportunity.
theregister.com
'It's not unusual for VoIP apps' says CEO
0
10
16
Thanks to @anton_chuvakin for our @SANSInstitute webinar on "SOC, Meet Cloud. Cloud, Meet SOC. What Changes — and What Stays the Same?" We also gave cloud detection examples for @splunk & @microsoft Sentinel & how to validate & test them. https://t.co/GceX5WE4b4
#SIEM #SecOps
0
0
3
Looking forward to an educational and entertaining conversation with @anton_chuvakin in our upcoming @SANSInstitute webinar on how #Cloud changes #SecOps! Register: https://t.co/cRTclCplmn
@CardinalOps
Many traditional #SOC teams have been challenged by the move to the #cloud and how this can change threat detection and IR. Reserve your spot for our live webinar (Jan 26 @ 1PM ET) produced by the @SANSInstitute and featuring @anton_chuvakin Register:
0
2
4
Big thanks to @anton_chuvakin for presenting at our Black Hat webinar, "SOC Modernization: Where Do We Go From Here?" Anton talked about why we need both process consistency (automation) and human creativity in the SOC. Watch on-demand: https://t.co/WdHX0F9vDb
@CardinalOps #cyber
0
5
30
Cybersecurity acronym salad still a mystery? @SANSInstitute @CRITICALSTART @anton_chuvakin can help. #XDR #SIEM #EDR #MDR
Join @anton_chuvakin, Head of Security Strategy A Google Cloud, and Randy Watkins, CTO @ Critical Start, for a live webinar w/ @SANSInstitute, as they explore "Demystifying #SIEM, #EDR, #XDR & #MDR". Register today: https://t.co/VEvCg9qkOd
#infosec #CyberSecurity #secops
1
3
5
How to communicate cyber risk to the C-level? Make it real (to the business), give examples, and keep it simple. @JohnBrennan #GartnerSEC
0
0
1
At #GartnerSEC, @JohnBrennan suggests Congress needs to change our statutory framework to allow govt. agencies to be more proactive in defending private sector from cyberattacks (since 85% of critical infrastructure owned by private sector)… maybe even retaliate? #CyberSecurity
0
0
2
If you're attending #splunkconf22, stop by booth M108 (near Theater A) on Wed. at 4pm to get your free signed copy of this detailed technical history of 0-day #cyber weapons. Written like a spy thriller, featuring hackers, bug-sellers & other crazy characters by @nicoleperlroth
0
2
5
Department of Justice Announces New Policy for Charging Cases under the Computer Fraud and Abuse Act https://t.co/6PtBNd7xtW
justice.gov
The Department of Justice today announced the revision of its policy regarding charging violations of the Computer Fraud and Abuse Act (CFAA).
54
100
179
2022 data-driven report on #MITRE ATT&CK coverage gaps in enterprise SIEMs shows actual detection coverage & detection quality are far below what most organizations assume. Thanks to @anton_chuvakin for his best practice recommendations in the report. https://t.co/t2w3KimO7f
2
6
13
#GoogleCloud’s survey today is another sign that its battle with #Microsoft in the #security market is intensifying: https://t.co/KjEVP4OBaI with insights from @bambenek @ayoran @misterbisson @rdecker99
#cybersecurity $MSFT $GOOG
0
3
3
SANS webinar featuring @anton_chuvakin about the future of #SIEM – and why many problems that plagued early SIEM users are still with us today. We'll also describe the state of @MITREattack coverage in real-world SIEM deployments. Register: https://t.co/sKqNIKFzP2
@SANSInstitute
0
5
5
"Hackers live in a realm between spaces and times, looking at the hidden connections and occasionally playing a chord on the threads." @daveaitel from "General Relativity is Not Evenly Distributed"
0
0
0
"As a defender, I am more scared about the uncontrollable growth of assets then about the growth of threats" -- [ well, frankly, this is a self-quote, but I catch myself using this a lot these days] :-)
2
9
59
“By promising to be API compatible (including offering S3's eleven-nines durability guarantee and free infrequent access), Cloudflare has cut off nearly all of AWS' remaining "liberties", putting it in "atari".” … and thanks to SCOTUS (ORCL v. GOOGL), you can’t copyright an API.
To quote Wikipedia, a move that overwhelmingly compels a player into a particular follow-up move is said to have "sente" (先手), or "initiative". In most games, the player who maintains "sente" most of the time will win. https://t.co/hDUOI1QvL8
0
0
0
“When a security person sees a vulnerability, they zoom out and see risk—they see an attacker and what they can access. On the other hand, when a developer thinks about a vulnerability, they see the app—what might go wrong and the maintenance cost of mitigating it.”
New Developer Den interview out with @guypod, Founder & President of @snyksec! Hear from Guy on optimizing developer experience, the best path to becoming a CTO, when to offer a freemium product, advice for devs early in their career + more. https://t.co/M3SkZbRYX0
0
0
2
Learn why Microsoft scored highest in threat visibility coverage for @MITREattack for ICS — and why lack of visibility into multi-stage IT/OT attacks like TRITON is a key ops risk. Thanks to @ojalexander + team for helping the community with this effort!
0
0
2