home.social

#opentide — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #opentide, aggregated by home.social.

fetched live
  1. @timb_machine I kind of like your post about how you threat model for customers in Cisco, it would be cool if you then extended the service to provide #OpenTide mapped threat graphs mapped to detections for them, as (some unnamed consulting houses) are doing.

  2. @timb_machine I kind of like your post about how you threat model for customers in Cisco, it would be cool if you then extended the service to provide #OpenTide mapped threat graphs mapped to detections for them, as (some unnamed consulting houses) are doing.

  3. @timb_machine One day when we read links like br0k3nlab.com/resources/axioms people will have read the #OpenTide white paper and realized how it changes the conversation about #detectioncoverage but this day was not today.

  4. @timb_machine One day when we read links like br0k3nlab.com/resources/axioms people will have read the #OpenTide white paper and realized how it changes the conversation about #detectioncoverage but this day was not today.

  5. Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.

    You can't and shouldn't use MITRE #ATT&CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.

    If you want to do any sort of data driven #detectioncoverage you need #OpenTide -> there's no way around it.

    levelup.gitconnected.com/why-t

    ATT&CK is still ♥️ 😍 tho.

    #SOC #blueteam #detectionEngineering

  6. Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.

    You can't and shouldn't use MITRE #ATT&CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.

    If you want to do any sort of data driven #detectioncoverage you need #OpenTide -> there's no way around it.

    levelup.gitconnected.com/why-t

    ATT&CK is still ♥️ 😍 tho.

    #SOC #blueteam #detectionEngineering

  7. @merill drop a few links too please. Did you (they) consider releasing the work also in #OpenTide format to increase actionability? OpenTide recently released the OpenTide version of the ATRM -> threat vectors only for now. Having this alongside would be huge.

    Also have been praising your newsletter to regional MS folks, don’t know if any of that filtered back to you. If not, thank you!

  8. @merill drop a few links too please. Did you (they) consider releasing the work also in #OpenTide format to increase actionability? OpenTide recently released the OpenTide version of the ATRM -> threat vectors only for now. Having this alongside would be huge.

    Also have been praising your newsletter to regional MS folks, don’t know if any of that filtered back to you. If not, thank you!

  9. This #detection #SOC post #detectfyi is very good, and I agree fully up to a point. Where my opinion, and #OpenTIDE starts to diverge is for the final paragraph on coverage discussions and documentation. Its possible to do better than this now. And detection depth as a number of detection points along an attack path is....not bad, actually innovative compared to most who don't even use a graph view, it may just not be the optimal type of detections to deploy in this case detect.fyi/critical-asset-anal

  10. This #detection #SOC post #detectfyi is very good, and I agree fully up to a point. Where my opinion, and #OpenTIDE starts to diverge is for the final paragraph on coverage discussions and documentation. Its possible to do better than this now. And detection depth as a number of detection points along an attack path is....not bad, actually innovative compared to most who don't even use a graph view, it may just not be the optimal type of detections to deploy in this case detect.fyi/critical-asset-anal

  11. @lojikil @circl Can I be honest?

    I hope I can and will presume it. This framework is not bad at all, but its inferior to #OpenTIDE by a lot :).

  12. @lojikil @circl Can I be honest?

    I hope I can and will presume it. This framework is not bad at all, but its inferior to #OpenTIDE by a lot :).

  13. RE: infosec.exchange/@cR0w/1152311

    Don't you wish we could also collaborate defensively, become force multipliers for each other?

    We can. Check out #OpenTIDE

  14. RE: infosec.exchange/@cR0w/1152311

    Don't you wish we could also collaborate defensively, become force multipliers for each other?

    We can. Check out #OpenTIDE

  15. #DetectionEngineering #OpenTIDE
    So #Cloudot will help you empirically map attack telemetry, create it and allow you to try to test your detections also

  16. #DetectionEngineering #OpenTIDE
    So #Cloudot will help you empirically map attack telemetry, create it and allow you to try to test your detections also

  17. Now Itay Gabbay releases Cloudot, a tool to help you with #DetectionEngineering in cloud.

    The tool looks like a serious chunk out of the #OpenTIDE backlog! #Cloudot

  18. Now Itay Gabbay releases Cloudot, a tool to help you with #DetectionEngineering in cloud.

    The tool looks like a serious chunk out of the #OpenTIDE backlog! #Cloudot

  19. @joshbressers you run the opensourcesecurity podcast then? Nice! Did you consider doing an episode on #OpenTIDE ?

  20. @joshbressers you run the opensourcesecurity podcast then? Nice! Did you consider doing an episode on #OpenTIDE ?

  21. @nopatience Sounds great. Now, for detection logic, if this gets shared as #OpenTIDE format, then some extra benefits accrue.

  22. @nopatience Sounds great. Now, for detection logic, if this gets shared as #OpenTIDE format, then some extra benefits accrue.

  23. If you’re #purpleteam ’ing without #OpenTIDE, why don’t you want your work to be actionable for your #SOC #DetectionEngineering :P

  24. If you’re #purpleteam ’ing without #OpenTIDE, why don’t you want your work to be actionable for your #SOC #DetectionEngineering :P

  25. From @BSidesLV 2024 -> Ezz uses ML to cluster events without any performance impact on the SIEM and using Attack Flows to help identify the right elements to try to cluster:

    youtube.com/watch?v=7KOoLo7oyn

    This will work excellently for #OpenTIDE TVMs also

    #DetectionEngineering

  26. From @BSidesLV 2024 -> Ezz uses ML to cluster events without any performance impact on the SIEM and using Attack Flows to help identify the right elements to try to cluster:

    youtube.com/watch?v=7KOoLo7oyn

    This will work excellently for #OpenTIDE TVMs also

    #DetectionEngineering

  27. Please everyone interested in #SOC or #DetectionEngineering read this by @letswastetime its a fantastic post: dispatch.thorcollective.com/p/

    I can only think of one thing missing - which is the actual enumeration of threat vectors and how they chain together to allow you to proceed with a data-driven approach to building your detection in depth.

    There's only one #opensource framework that allows us to do the chaining as a community - and you know its #OpenTIDE

  28. Please everyone interested in #SOC or #DetectionEngineering read this by @letswastetime its a fantastic post: dispatch.thorcollective.com/p/

    I can only think of one thing missing - which is the actual enumeration of threat vectors and how they chain together to allow you to proceed with a data-driven approach to building your detection in depth.

    There's only one #opensource framework that allows us to do the chaining as a community - and you know its #OpenTIDE

  29. @Regit @circl @suricata imagine how much better that export would be if it was in #OpenTIDE format as MISP OpenTIDE objects.

  30. @Regit @circl @suricata imagine how much better that export would be if it was in #OpenTIDE format as MISP OpenTIDE objects.

  31. This post by Jamie Williams on the THOR Dispatch collective dispatch.thorcollective.com/p/ See Evil, Thrunt Evil – Modelling Behaviors is a Critical Thrunting Prerequisite is very correct in that it says you need to not look at threat actor activities in isolation. Which is why #OpenTIDE allows you to chain threat vector models together, creating attack paths.

    Shame its on #substack Jamie/ThorCollective.

  32. This post by Jamie Williams on the THOR Dispatch collective dispatch.thorcollective.com/p/ See Evil, Thrunt Evil – Modelling Behaviors is a Critical Thrunting Prerequisite is very correct in that it says you need to not look at threat actor activities in isolation. Which is why #OpenTIDE allows you to chain threat vector models together, creating attack paths.

    Shame its on #substack Jamie/ThorCollective.

  33. According to new data, we’re really reaping the benefits of #OpenTIDE now in terms of exclusively release speed (#detectionengineering) and release quality. Not even talking about all the other advantages, but those 2 numbers alone are stunning now.

  34. According to new data, we’re really reaping the benefits of #OpenTIDE now in terms of exclusively release speed (#detectionengineering) and release quality. Not even talking about all the other advantages, but those 2 numbers alone are stunning now.

  35. @timb_machine My idea for the backlog #OpenTIDE implementation of this is a per-detection community feedback module where you can rate TVMs, CDMs and detection rule proposals on the fit with your vertical, company size, region, etc

  36. @timb_machine My idea for the backlog #OpenTIDE implementation of this is a per-detection community feedback module where you can rate TVMs, CDMs and detection rule proposals on the fit with your vertical, company size, region, etc

  37. @cybersecdiva While that's definitely not a bad project, if you tried it, then please try #OpenTIDE after and let me know how you think they compare?

  38. @cybersecdiva While that's definitely not a bad project, if you tried it, then please try #OpenTIDE after and let me know how you think they compare?

  39. My former team published the whitepaper for OpenTIDE (Open Threat Informed Detection Engineering), a next-generation Detection Engineering framework aimed at powering and interconnecting SOCs with common best practices and way of working. #OpenTIDE was incubated 2 years at the European Commission, where it was used as a catalyst to create a new Detection Engineering capacity.

    1/2

  40. My former team published the whitepaper for OpenTIDE (Open Threat Informed Detection Engineering), a next-generation Detection Engineering framework aimed at powering and interconnecting SOCs with common best practices and way of working. #OpenTIDE was incubated 2 years at the European Commission, where it was used as a catalyst to create a new Detection Engineering capacity.

    1/2

  41. Very proud to see Amine on the Google Cloud Security podcast with @Timothypeacock and @anton_chuvakin

    Go listen to episode 202 on SOCs, #DetectionEngineering and #OpenTIDE

  42. Very proud to see Amine on the Google Cloud Security podcast with @Timothypeacock and @anton_chuvakin

    Go listen to episode 202 on SOCs, #DetectionEngineering and #OpenTIDE

  43. AND we have a John Lambert name drop for the famous blog post, which we of course also quote in the #OpenTIDE white paper github.com/JohnLaTwC/Shared/bl

    Nice to couple the #kubehound graph attack view with Lambert’s famous blog.

    Now now now-> how to detect this? Graph it out! In #OpenTIDE!

  44. AND we have a John Lambert name drop for the famous blog post, which we of course also quote in the #OpenTIDE white paper github.com/JohnLaTwC/Shared/bl

    Nice to couple the #kubehound graph attack view with Lambert’s famous blog.

    Now now now-> how to detect this? Graph it out! In #OpenTIDE!

  45. At @hack_lu #hacklu2024 Jeroen Pinoy concludes that the #MITRE #ATTA&K framework doesn’t have sufficient granularity to enable researchers and defenders to tell cloaking from other events/threat vectors.

    Hint: You can model this in #OpenTIDE :)

  46. At @hack_lu #hacklu2024 Jeroen Pinoy concludes that the #MITRE #ATTA&K framework doesn’t have sufficient granularity to enable researchers and defenders to tell cloaking from other events/threat vectors.

    Hint: You can model this in #OpenTIDE :)

  47. @magoo making CTI 'actionable' after all of which they still produce outputs that are decidedly not actionable for DE teams, leaving DE teams again stuck in duplication of effort, this time duplicating the efforts of CTI, or DFIR, or the RT to understand wtaf happened for a specific threat vector at the level of granularity that DE works at and needs to work at.

    And then you get tired. And if you're really smart, and follow me, then you find #OpenTIDE
    ♥️

  48. @magoo making CTI 'actionable' after all of which they still produce outputs that are decidedly not actionable for DE teams, leaving DE teams again stuck in duplication of effort, this time duplicating the efforts of CTI, or DFIR, or the RT to understand wtaf happened for a specific threat vector at the level of granularity that DE works at and needs to work at.

    And then you get tired. And if you're really smart, and follow me, then you find #OpenTIDE
    ♥️