Devon Kerr (@_devonkerr_) 's Twitter Profile
Devon Kerr

@_devonkerr_

Director of @ElasticSecLabs and custodian of secret histories, making environments hostile to threats since 2010. Posts are my own.

ID: 2843933755

linkhttp://elastic.co/security-labs calendar_today07-10-2014 17:23:21

11,11K Tweet

7,7K Followers

699 Following

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

Thoughts on LLMs writing detection rules, and why I’m not impressed: LLMs are good at one thing – predicting the next most plausible word in a sentence. That’s why most AI-generated detection rules are only good at one thing as well: looking plausible. On first glance they seem

Patrick Wardle (@patrickwardle) 's Twitter Profile Photo

Just posted my DEF CON slides (talk #1): "Mastering Apple's Endpoint Security for Advanced macOS Malware Detection" Writing 🍎 security software? You should be using Endpoint Security! But its advanced features are rather nuanced & often misunderstood 🫣 speakerdeck.com/patrickwardle/…

Andrew Thompson (@imposecost) 's Twitter Profile Photo

I think people who only live in a world where potential victims merely harden against attack are the naive ones. In my world, the "victims" are targets, and they hit back. But please adversary-splain me. 😆

MG (@_mg_) 's Twitter Profile Photo

Andrew Thompson “and your freedom is gone” would be a great way to destroy defcon’s brand and comes off as extreme punishment for a kid throwing sand in a sandbox. However your post does exhibit a commonality with why we have this issue: lack of contextual nuance. We have far too few people

<a href="/ImposeCost/">Andrew Thompson</a> “and your freedom is gone” would be a great way to destroy defcon’s brand and comes off as extreme punishment for a kid throwing sand in a sandbox.  However your post does exhibit a commonality with why we have this issue: lack of contextual nuance. 

We have far too few people
Greg Lesnewich (@greglesnewich) 's Twitter Profile Photo

Devon Kerr I think I feel like I can breathe for a second when I can reliably detect or disrupt their activity across 60% or more of the collection+stack I have available

Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

[New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering If you ever struggle with false positives and the idea of tuning detections. This is for you. Read More - nasbench.medium.com/the-fragile-ba…

[New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering

If you ever struggle with false positives and the idea of tuning detections. This is for you.

Read More - nasbench.medium.com/the-fragile-ba…
Matt Anderson (@nosecurething) 's Twitter Profile Photo

Nasreddine Bencherchali Good stuff! Love the details here. One thing that gives me confidence to tune aggressively (maintain some level of coverage rather than scrapping a rule completely) is using a layered detection approach. What you give up in one rule you can get back or cover in another.

Andrew Thompson (@imposecost) 's Twitter Profile Photo

One thing I tell leaders privately but will say here is you're a human being like everyone else. You're not a punching bag. There are some people in this world that perceive any social or institutional hierarchical level difference as a free pass to be abusive upwards. Be kind to

Olivia Gallucci ✨ (@oliviagalluccii) 's Twitter Profile Photo

My academic career has come to a close. I completed my 3rd (and final) graduation from RIT—this time with an MBA! 🎓 Huge thanks to my mentors and friends who have inspired me and challenged me to pursue Apple security, FOSS, and business: Alex Beaver, Dylan,

My academic career has come to a close. I completed my 3rd (and final) graduation from <a href="/RITtigers/">RIT</a>—this time with an MBA! 🎓

Huge thanks to my mentors and friends who have inspired me and challenged me to pursue Apple security, FOSS, and business: <a href="/alexcbeaver/">Alex Beaver</a>, <a href="/InsecureNature/">Dylan</a>,
BSidesNoVA (@bsides_nova) 's Twitter Profile Photo

What are your plans for tonight? Yeah. I thought so. Hey, our #BSidesNoVA 2025 #CFP is open until 11:59pm ET. Put on that garbage tv show. Order some food. Give us a cool #InfoSec proposal! Security BSides is self-care. We said so. sessionize.com/bsidesnova-202…

What are your plans for tonight? 

Yeah. I thought so. 

Hey, our #BSidesNoVA 2025 #CFP is open until 11:59pm ET. 

Put on that garbage tv show. Order some food. Give us a cool #InfoSec proposal! <a href="/SecurityBSides/">Security BSides</a> is self-care. We said so. 
sessionize.com/bsidesnova-202…
hogfly 🌻 (@4n6ir) 's Twitter Profile Photo

I think more people need to spend time evaluating mcp, architecting it, governing it and uh…abusing/testing it to understand the limitations and vectors for compromise.

Devon Kerr (@_devonkerr_) 's Twitter Profile Photo

Every now and then I’m reminded how much content here is just lazy repackaging by uninformed folks engagement farming, which shows a lack of judgment and integrity on account of how much less work it is to simply retweet— but then monetization is impacted…