
Devon Kerr
@_devonkerr_
Director of @ElasticSecLabs and custodian of secret histories, making environments hostile to threats since 2010. Posts are my own.
ID: 2843933755
http://elastic.co/security-labs 07-10-2014 17:23:21
11,11K Tweet
7,7K Followers
699 Following






Andrew Thompson “and your freedom is gone” would be a great way to destroy defcon’s brand and comes off as extreme punishment for a kid throwing sand in a sandbox. However your post does exhibit a commonality with why we have this issue: lack of contextual nuance. We have far too few people


Devon Kerr I think I feel like I can breathe for a second when I can reliably detect or disrupt their activity across 60% or more of the collection+stack I have available


Nasreddine Bencherchali Good stuff! Love the details here. One thing that gives me confidence to tune aggressively (maintain some level of coverage rather than scrapping a rule completely) is using a layered detection approach. What you give up in one rule you can get back or cover in another.




What are your plans for tonight? Yeah. I thought so. Hey, our #BSidesNoVA 2025 #CFP is open until 11:59pm ET. Put on that garbage tv show. Order some food. Give us a cool #InfoSec proposal! Security BSides is self-care. We said so. sessionize.com/bsidesnova-202…


