Ross Wolf
@rw_access
Followers
1K
Following
4K
Media
75
Statuses
630
fan of the absurd. engineer for @Sublime_Sec. previously at @Elastic @EndgameInc @MITREcorp https://t.co/Jvf9O8HJvM
Colorado
Joined June 2018
@sublime_sec TL;DR How to make ~90% similarity search Instead of one hash for a 100% match, 1. Use many min hashes (400-500) 2. Group those into a handful of big hashes (10-20) 3. Find an exact matching big hash to get close 4. Count matching small hashes to calculate similarity
0
0
1
I'm definitely feeling warm and fuzzy hashes this holiday season. Fast similarity is something that stumped me for a very long time, but MinHash turned out to be an elegant solution! Wrote up how to build it from scratch on the @sublime_sec blog
Grouping similar emails creates herd immunity and boosts analyst productivity. We built a low-latency similarity system that groups millions of messages in milliseconds. Technical deep dive:
1
0
4
We’re excited to announce that Sublime has raised $150M in a Series C led by @Georgian_io, joined by new investors @Avenir_Growth, @01Advisors, @jonoberheide, and @nicoleperlroth, and existing investors @IndexVentures, @IVP, @slow, and @CitiVentures. This year we launched ASA
1
7
31
go get yourself some @MITREattack T1667 coverage
Introducing email bomb protection from Sublime: a powerful solution for automatically detecting, remediating, and triaging email bombs. In these attacks, an adversary will send hundreds or thousands of emails at once to flood an inbox and obfuscate the malicious intent. Learn how
0
0
3
Introducing email bomb protection from Sublime: a powerful solution for automatically detecting, remediating, and triaging email bombs. In these attacks, an adversary will send hundreds or thousands of emails at once to flood an inbox and obfuscate the malicious intent. Learn how
1
3
10
this was a very cool problem to solve with @filar! It's such a natural evolution of the platform, which has been group-centric since day 1. Fellow nerds, look out for an engineering post about how "fuzzy" grouping works and the scaling+realtime challenges we had to overcome
Mass volume email attack campaigns are often customized to the recipient to increase legitimacy. We recently improved our campaign grouping algorithm to be better at identifying similar messages in a campaign to cut review time, reduce alerts, and boost herd immunity. Read how
0
3
16
if a rule is too complex to understand, the alert is even worse
1
2
5
don't practice Scanteria, just use our QRystal ball
It's been a busy week for QR code phishing, so @samkscholten put together a deep dive on how Sublime detects and decodes these email attacks with our open source rules: https://t.co/K2PErgWTlf
0
1
8
I know it's a running joke about everyone boasting 100% MITRE Engenuity scores but please actually read the results, they provide a lot more nuance and insight into how the products performed and at what level of specificity
1
6
25
Happy to share what I've working on in the last year- Unveiling Elasticsearch Query Language (ES|QL)
elastic.co
The Elasticsearch Query Language (ES|QL) has been added to the Elasticsearch repository. ES|QL is a powerful declarative language that's native to Elasticsearch and designed for composability,...
1
15
56
Our DEF CON 31 workshop may be full, but there are some spots still available @BSidesLV on Aug 9. Come hunt for various email attack types in a lab environment w/ @jkamdjou and @ajpc500! https://t.co/scl43enzLN
1
7
10
🔊 New blog post: Part 2 of the “Creating a full-text search engine using PostgreSQL” series. In this one we are comparing the Postgres search functionality to Elasticsearch. https://t.co/8k9vY2WSsT
xata.io
Using PostgreSQL as a full-text search engine is tempting because it requires less infrastructure. But is its set of search-related features enough to compete with the Lucene based alternatives?
0
5
12
Much of modern ML engineering is making Python not be your bottleneck.
90
122
2K
there's something ironic about a solicitor at your front door that's in the business of pest control.
1
0
2
To be clear if you die wearing the vision pro you die in the real world.
0
1
5
no need to worry about new .zip domains in an email body if you're rocking @sublime_sec. we already have logic for domain age checks, so you're set https://t.co/dnPsGTvOuG
1
4
23