#opentide — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #opentide, aggregated by home.social.
-
RE: https://infosec.exchange/@letswastetime/116448373357473541
Now port these hunts to #OpenTide format and help the world.
-
RE: https://infosec.exchange/@letswastetime/116448373357473541
Now port these hunts to #OpenTide format and help the world.
-
-
-
@timb_machine I kind of like your post about how you threat model for customers in Cisco, it would be cool if you then extended the service to provide #OpenTide mapped threat graphs mapped to detections for them, as (some unnamed consulting houses) are doing.
-
@timb_machine I kind of like your post about how you threat model for customers in Cisco, it would be cool if you then extended the service to provide #OpenTide mapped threat graphs mapped to detections for them, as (some unnamed consulting houses) are doing.
-
@timb_machine One day when we read links like https://br0k3nlab.com/resources/axioms-of-security-and-rule-based-capabilities/ people will have read the #OpenTide white paper and realized how it changes the conversation about #detectioncoverage but this day was not today.
-
@timb_machine One day when we read links like https://br0k3nlab.com/resources/axioms-of-security-and-rule-based-capabilities/ people will have read the #OpenTide white paper and realized how it changes the conversation about #detectioncoverage but this day was not today.
-
-
-
Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.
You can't and shouldn't use MITRE #ATT&CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.
If you want to do any sort of data driven #detectioncoverage you need #OpenTide -> there's no way around it.
https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
ATT&CK is still ♥️ 😍 tho.
-
Despite the promising title of this blog post by John Vester 'Why the MITRE ATT&CK Framework Actually Works', its a load of crock.
You can't and shouldn't use MITRE #ATT&CK to prove any sort of detection coverage or 'strong points'. At best, you can prove total absence in certain subtechniques.
If you want to do any sort of data driven #detectioncoverage you need #OpenTide -> there's no way around it.
https://levelup.gitconnected.com/why-the-mitre-att-ck-framework-actually-works-29ac26d2d20c
ATT&CK is still ♥️ 😍 tho.
-
@merill drop a few links too please. Did you (they) consider releasing the work also in #OpenTide format to increase actionability? OpenTide recently released the OpenTide version of the ATRM -> threat vectors only for now. Having this alongside would be huge.
Also have been praising your newsletter to regional MS folks, don’t know if any of that filtered back to you. If not, thank you!
-
@merill drop a few links too please. Did you (they) consider releasing the work also in #OpenTide format to increase actionability? OpenTide recently released the OpenTide version of the ATRM -> threat vectors only for now. Having this alongside would be huge.
Also have been praising your newsletter to regional MS folks, don’t know if any of that filtered back to you. If not, thank you!
-
This #detection #SOC post #detectfyi is very good, and I agree fully up to a point. Where my opinion, and #OpenTIDE starts to diverge is for the final paragraph on coverage discussions and documentation. Its possible to do better than this now. And detection depth as a number of detection points along an attack path is....not bad, actually innovative compared to most who don't even use a graph view, it may just not be the optimal type of detections to deploy in this case https://detect.fyi/critical-asset-analysis-for-detection-engineering-72b8051df149
-
This #detection #SOC post #detectfyi is very good, and I agree fully up to a point. Where my opinion, and #OpenTIDE starts to diverge is for the final paragraph on coverage discussions and documentation. Its possible to do better than this now. And detection depth as a number of detection points along an attack path is....not bad, actually innovative compared to most who don't even use a graph view, it may just not be the optimal type of detections to deploy in this case https://detect.fyi/critical-asset-analysis-for-detection-engineering-72b8051df149
-
RE: https://infosec.exchange/@cR0w/115231138483939791
Don't you wish we could also collaborate defensively, become force multipliers for each other?
We can. Check out #OpenTIDE
-
RE: https://infosec.exchange/@cR0w/115231138483939791
Don't you wish we could also collaborate defensively, become force multipliers for each other?
We can. Check out #OpenTIDE
-
#DetectionEngineering #OpenTIDE
So #Cloudot will help you empirically map attack telemetry, create it and allow you to try to test your detections also -
#DetectionEngineering #OpenTIDE
So #Cloudot will help you empirically map attack telemetry, create it and allow you to try to test your detections also -
Now Itay Gabbay releases Cloudot, a tool to help you with #DetectionEngineering in cloud.
The tool looks like a serious chunk out of the #OpenTIDE backlog! #Cloudot
-
Now Itay Gabbay releases Cloudot, a tool to help you with #DetectionEngineering in cloud.
The tool looks like a serious chunk out of the #OpenTIDE backlog! #Cloudot
-
-
-
@joshbressers you run the opensourcesecurity podcast then? Nice! Did you consider doing an episode on #OpenTIDE ?
-
@joshbressers you run the opensourcesecurity podcast then? Nice! Did you consider doing an episode on #OpenTIDE ?
-
@nopatience Sounds great. Now, for detection logic, if this gets shared as #OpenTIDE format, then some extra benefits accrue.
-
@nopatience Sounds great. Now, for detection logic, if this gets shared as #OpenTIDE format, then some extra benefits accrue.
-
If you’re #purpleteam ’ing without #OpenTIDE, why don’t you want your work to be actionable for your #SOC #DetectionEngineering :P
-
If you’re #purpleteam ’ing without #OpenTIDE, why don’t you want your work to be actionable for your #SOC #DetectionEngineering :P
-
From @BSidesLV 2024 -> Ezz uses ML to cluster events without any performance impact on the SIEM and using Attack Flows to help identify the right elements to try to cluster:
https://www.youtube.com/watch?v=7KOoLo7oynk&list=PLjpIlpOLoRNQ0vzGtdcFyKNUA8JrpoM48&index=92
This will work excellently for #OpenTIDE TVMs also
-
From @BSidesLV 2024 -> Ezz uses ML to cluster events without any performance impact on the SIEM and using Attack Flows to help identify the right elements to try to cluster:
https://www.youtube.com/watch?v=7KOoLo7oynk&list=PLjpIlpOLoRNQ0vzGtdcFyKNUA8JrpoM48&index=92
This will work excellently for #OpenTIDE TVMs also
-
Please everyone interested in #SOC or #DetectionEngineering read this by @letswastetime its a fantastic post: https://dispatch.thorcollective.com/p/detection-in-depth
I can only think of one thing missing - which is the actual enumeration of threat vectors and how they chain together to allow you to proceed with a data-driven approach to building your detection in depth.
There's only one #opensource framework that allows us to do the chaining as a community - and you know its #OpenTIDE
-
Please everyone interested in #SOC or #DetectionEngineering read this by @letswastetime its a fantastic post: https://dispatch.thorcollective.com/p/detection-in-depth
I can only think of one thing missing - which is the actual enumeration of threat vectors and how they chain together to allow you to proceed with a data-driven approach to building your detection in depth.
There's only one #opensource framework that allows us to do the chaining as a community - and you know its #OpenTIDE
-
This post by Jamie Williams on the THOR Dispatch collective https://dispatch.thorcollective.com/p/see-evil-thrunt-evil-modelling-behaviors See Evil, Thrunt Evil – Modelling Behaviors is a Critical Thrunting Prerequisite is very correct in that it says you need to not look at threat actor activities in isolation. Which is why #OpenTIDE allows you to chain threat vector models together, creating attack paths.
Shame its on #substack Jamie/ThorCollective.
-
This post by Jamie Williams on the THOR Dispatch collective https://dispatch.thorcollective.com/p/see-evil-thrunt-evil-modelling-behaviors See Evil, Thrunt Evil – Modelling Behaviors is a Critical Thrunting Prerequisite is very correct in that it says you need to not look at threat actor activities in isolation. Which is why #OpenTIDE allows you to chain threat vector models together, creating attack paths.
Shame its on #substack Jamie/ThorCollective.
-
According to new data, we’re really reaping the benefits of #OpenTIDE now in terms of exclusively release speed (#detectionengineering) and release quality. Not even talking about all the other advantages, but those 2 numbers alone are stunning now.
-
According to new data, we’re really reaping the benefits of #OpenTIDE now in terms of exclusively release speed (#detectionengineering) and release quality. Not even talking about all the other advantages, but those 2 numbers alone are stunning now.
-
@timb_machine My idea for the backlog #OpenTIDE implementation of this is a per-detection community feedback module where you can rate TVMs, CDMs and detection rule proposals on the fit with your vertical, company size, region, etc
-
@timb_machine My idea for the backlog #OpenTIDE implementation of this is a per-detection community feedback module where you can rate TVMs, CDMs and detection rule proposals on the fit with your vertical, company size, region, etc
-
@cybersecdiva While that's definitely not a bad project, if you tried it, then please try #OpenTIDE after and let me know how you think they compare?
-
@cybersecdiva While that's definitely not a bad project, if you tried it, then please try #OpenTIDE after and let me know how you think they compare?
-
ChatGPT on how #opentide contributes to #detectionengineering and making #CTI actionable
-
ChatGPT on how #opentide contributes to #detectionengineering and making #CTI actionable
-
My former team published the whitepaper for OpenTIDE (Open Threat Informed Detection Engineering), a next-generation Detection Engineering framework aimed at powering and interconnecting SOCs with common best practices and way of working. #OpenTIDE was incubated 2 years at the European Commission, where it was used as a catalyst to create a new Detection Engineering capacity.
1/2
-
My former team published the whitepaper for OpenTIDE (Open Threat Informed Detection Engineering), a next-generation Detection Engineering framework aimed at powering and interconnecting SOCs with common best practices and way of working. #OpenTIDE was incubated 2 years at the European Commission, where it was used as a catalyst to create a new Detection Engineering capacity.
1/2
-
Very proud to see Amine on the Google Cloud Security podcast with @Timothypeacock and @anton_chuvakin
Go listen to episode 202 on SOCs, #DetectionEngineering and #OpenTIDE
-
Very proud to see Amine on the Google Cloud Security podcast with @Timothypeacock and @anton_chuvakin
Go listen to episode 202 on SOCs, #DetectionEngineering and #OpenTIDE
-
AND we have a John Lambert name drop for the famous blog post, which we of course also quote in the #OpenTIDE white paper https://github.com/JohnLaTwC/Shared/blob/master/Defenders%20think%20in%20lists.%20Attackers%20think%20in%20graphs.%20As%20long%20as%20this%20is%20true%2C%20attackers%20win.md
Nice to couple the #kubehound graph attack view with Lambert’s famous blog.
Now now now-> how to detect this? Graph it out! In #OpenTIDE!
-
AND we have a John Lambert name drop for the famous blog post, which we of course also quote in the #OpenTIDE white paper https://github.com/JohnLaTwC/Shared/blob/master/Defenders%20think%20in%20lists.%20Attackers%20think%20in%20graphs.%20As%20long%20as%20this%20is%20true%2C%20attackers%20win.md
Nice to couple the #kubehound graph attack view with Lambert’s famous blog.
Now now now-> how to detect this? Graph it out! In #OpenTIDE!
-
At @hack_lu #hacklu2024 Jeroen Pinoy concludes that the #MITRE #ATTA&K framework doesn’t have sufficient granularity to enable researchers and defenders to tell cloaking from other events/threat vectors.
Hint: You can model this in #OpenTIDE :)
-
At @hack_lu #hacklu2024 Jeroen Pinoy concludes that the #MITRE #ATTA&K framework doesn’t have sufficient granularity to enable researchers and defenders to tell cloaking from other events/threat vectors.
Hint: You can model this in #OpenTIDE :)
-
@magoo making CTI 'actionable' after all of which they still produce outputs that are decidedly not actionable for DE teams, leaving DE teams again stuck in duplication of effort, this time duplicating the efforts of CTI, or DFIR, or the RT to understand wtaf happened for a specific threat vector at the level of granularity that DE works at and needs to work at.
And then you get tired. And if you're really smart, and follow me, then you find #OpenTIDE
♥️ -
@magoo making CTI 'actionable' after all of which they still produce outputs that are decidedly not actionable for DE teams, leaving DE teams again stuck in duplication of effort, this time duplicating the efforts of CTI, or DFIR, or the RT to understand wtaf happened for a specific threat vector at the level of granularity that DE works at and needs to work at.
And then you get tired. And if you're really smart, and follow me, then you find #OpenTIDE
♥️