
Richard Bejtlich πΎ πΊπ¦
@taosecurity
Inactive on Twitter since 1 November 2022. Find me here: infosec.exchange/@taosecurity
ID: 17767238
https://taosecurity.blogspot.com 01-12-2008 00:49:30
23,23K Tweet
56,56K Followers
38 Following




In 2019 I wrote a blog for Corelight, "Network security monitoring is dead, and encryption killed it." My goal was to debunk that long-standing myth. Apparently at least 1 security company didn't get the point. π€¦ββοΈ#NSMlives despite encryption. Pls see: corelight.com/blog/examiningβ¦


I highly recommend this BSidesAugusta talk by David J. Bianco on his #PyramidofPain. He explains how we implemented a strategy (10+ years ago) to detect and respond to intrusions before adversary mission completion, via threat intelligence-driven campaigns. youtube.com/watch?v=3Xrl6Iβ¦







This is not a late "April Fool." This is real. I've been waiting months to say it. Now it's public. Microsoft is embedding The Zeek Network Security Monitor into Windows. This brings #networksecuritymonitoring to a potential billion+ endpoints. Hear Microsoft's take, Thu-Fri: zeek.org/zeekweek2022/

Speaking of Microsoft embedding The Zeek Network Security Monitor into Windows, here's a post I wrote in 2008 explaining why and how #networksecuritymonitoring on the endpoint would be helpful. It's so cool to see a concrete step in this direction, on a massively-deployed OS: taosecurity.blogspot.com/2008/02/nsm-atβ¦




Iβm concerned that Putin is planning a repeat of his 1999 Moscow apartment bombing. Iβm worried he orders use of a βdirty bombβ in UA, maybe Kherson, and then blames it on UA. Heβs already learned from recent Western tactics to give public early warning, except his would be lies.

As an ex-U.S. Air Force intel officer who was active duty in 1999, I enjoyed the new book "Shooting Down the Stealth Fighter," by the Serb personnel manning the S-125/SA-3. It's mostly about IADS, but it offers a ton of unclass details for #airpower fans. #ad amzn.to/3W9mBeX

