 
                                Devon Kerr
@_devonkerr_
Director of @ElasticSecLabs and custodian of secret histories, making environments hostile to threats since 2010. Posts are my own.
ID: 2843933755
http://elastic.co/security-labs 07-10-2014 17:23:21
11,11K Tweet
7,7K Takipçi
699 Takip Edilen
 
         
         
         
         
         
        Andrew Thompson “and your freedom is gone” would be a great way to destroy defcon’s brand and comes off as extreme punishment for a kid throwing sand in a sandbox. However your post does exhibit a commonality with why we have this issue: lack of contextual nuance. We have far too few people
 
                        
                    
                    
                    
                 
        Devon Kerr I think I feel like I can breathe for a second when I can reliably detect or disrupt their activity across 60% or more of the collection+stack I have available
 
         
        Nasreddine Bencherchali Good stuff! Love the details here. One thing that gives me confidence to tune aggressively (maintain some level of coverage rather than scrapping a rule completely) is using a layered detection approach. What you give up in one rule you can get back or cover in another.
 
         
         
         
        What are your plans for tonight? Yeah. I thought so. Hey, our #BSidesNoVA 2025 #CFP is open until 11:59pm ET. Put on that garbage tv show. Order some food. Give us a cool #InfoSec proposal! Security BSides is self-care. We said so. sessionize.com/bsidesnova-202…
 
                        
                    
                    
                    
                 
         
         
        ![Nasreddine Bencherchali (@nas_bench) on Twitter photo [New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering
If you ever struggle with false positives and the idea of tuning detections. This is for you.
Read More - nasbench.medium.com/the-fragile-ba… [New Blog 📚] The Fragile Balance: Assumptions, Tuning, and Telemetry Limits In Detection Engineering
If you ever struggle with false positives and the idea of tuning detections. This is for you.
Read More - nasbench.medium.com/the-fragile-ba…](https://pbs.twimg.com/media/GyRUjGIXcAUxKst.jpg) 
                        