Discussion about this post

User's avatar
Neural Foundry's avatar

Great issue Zack! The critical asset analysis piece resonated - Gary Katz's approach of focusing on 'chokepoints' rather than chasing 100% MITRE coverage is exactly what practical detection engineering should look like. Katie's CoPhish research is particularly timely given how fast AI features are shipping. The OAuth consent phishing angle is clever - users are already trained to click through Microsoft auth prompts, so the attack surface is huge. The Group 78 revelations were fascinating too - if the ExploitWhisperer leak really came from them, that's next-level disruption tactics. On a lighter note, hope your ribs heal up soon - ER docs underestimating rib pain is a universal experiance!

Expand full comment
Rainbow Roxy's avatar

Hey, great read as always. With detections.ai using AI to generate rules, I wonder if you see that shifting the bottleneck from rule creation to the actual processing and human interpretation of the increased alerts that AI SOCs generate? You realy always have such insightful takes on these complex topics, it's genuinely fascinating to follow.

Expand full comment
1 more comment...

No posts

Ready for more?