Josh Brower (@defensivedepth) 's Twitter Profile
Josh Brower

@defensivedepth

Husband, Father. InfoSec. SANS GSE #143. Course author of LearnOsquery.com & LearnSigmaRules.com. Lover of History, Coffee, and D&D. Chaotic Good. He/Him

ID: 15827547

linkhttp://DefensiveDepth.com calendar_today12-08-2008 20:25:55

2,2K Tweet

2,2K Followers

727 Following

Chris Sanders πŸ”Ž 🧠 (@chrissanders88) 's Twitter Profile Photo

A week from now, I'll be speaking at Security Onion con alongside my good friend Josh Brower. We'll talk about human-centric investigation playbooks and how those manifest in Security Onion now. Hope to see you there in Augusta! securityonionsolutions.com/conference/

Florian Roth ⚑️ (@cyb3rops) 's Twitter Profile Photo

We’d love to see more feedback from orgs that rely on Sigma rules Even simple stats from production use are valuable. - A rule of level high that triggered 236,992 times probably needs rework. - A rule of level critical that triggered 234 times probably needs rework. - A rule of

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

New Sigma release r2025-10-01 is available for download. 🌟37 New Rules πŸ›‘οΈ16 Rule updates πŸ”¬45 Rule Fixes Here is a quick overview: - New AWS and Github based rules covering deletion of VPC flows, KMS imports, changing archive status or pages of a repo - Winrs usage as a

New Sigma release r2025-10-01 is available for download.

🌟37 New Rules
πŸ›‘οΈ16 Rule updates
πŸ”¬45 Rule Fixes

Here is a quick overview:

- New AWS and Github based rules covering deletion of VPC flows, KMS imports, changing archive status or pages of a repo

- Winrs usage as a
Chris Sanders πŸ”Ž 🧠 (@chrissanders88) 's Twitter Profile Photo

Why do investigative playbooks work? #SOC #DFIR 1. In any given investigation, analysts ask investigative questions that they answer with data (evidence) to determine what happened and if malicious activity occurred.

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

Regression (True Positive) testing is coming to sigma starting from the next rule release in December. We will introduce a new CI that will validate a rule against a log. We will start with EVTX logs and extend beyond to other formats and logsources We're also introducing a

Regression (True Positive) testing is coming to <a href="/sigma_hq/">sigma</a> starting from the next rule release in December.
We will introduce a new CI that will validate a rule against a log. We will start with EVTX logs and extend beyond to other formats and logsources

We're also introducing a
Owlcat Games (@owlcatgames) 's Twitter Profile Photo

We have just released Rue Valley! This narrative RPG, inspired by games like Disco Elysium and classic Lucas Arts adventures, was developed by Emotion Spark Studio, and we helped them along the way as a publisher. Check out Rue Valley Release Trailer: #RueValley #RueValleyGame

Chris Sanders πŸ”Ž 🧠 (@chrissanders88) 's Twitter Profile Photo

LIFTOFF! All my courses on networkdefense.io are 25% off until Tuesday, 12/2, at midnight ET πŸš€ This is the only sitewide sale we do all year, and the cheapest you'll see these courses. This event is for all y'all, so to get the discount, use code ALLYALL at checkout.

LIFTOFF! All my courses on networkdefense.io are 25% off until Tuesday, 12/2, at midnight ET πŸš€

This is the only sitewide sale we do all year, and the cheapest you'll see these courses.

This event is for all y'all, so to get the discount, use code ALLYALL at checkout.
Josh Brower (@defensivedepth) 's Twitter Profile Photo

Good news everyone! 25% off my "Detection Engineering with Sigma" course! Use code "ALLYALL" at checkout. LearnSigmaRules.com #DetectionEngineering #InfoSec #SIGMA sigma Applied Network Defense

Security Onion (@securityonion) 's Twitter Profile Photo

Security Onion 2.4.200 now available with major improvements for our popular Onion AI Assistant! blog.securityonion.net/2025/12/securi…

Runa Sandvik (@runasand) 's Twitter Profile Photo

I started Granitt in 2022 to help journalists and other groups of at-risk people continue to do their work safely and securely. Please get in touch if you’re looking for an assessment, policy and process development, training, or presentation. techcrunch.com/2022/07/15/gra…

Adam Steinbaugh (@adamsteinbaugh) 's Twitter Profile Photo

Here is the newly-unsealed State Department memo confirming -- finally -- that the detention of Tufts student RΓΌmeysa Γ–ztΓΌrk was based on an op-ed. No antisemitic activity. No support of terrorism. An op-ed in a student newspaper.

Here is the newly-unsealed State Department memo confirming -- finally -- that the detention of Tufts student RΓΌmeysa Γ–ztΓΌrk was based on an op-ed.

No antisemitic activity. No support of terrorism.

An op-ed in a student newspaper.
Security Onion (@securityonion) 's Twitter Profile Photo

We've updated our popular Security Onion Essentials video series! Peel back the layers and make your adversaries cry! youtube.com/playlist?list=…