reSee.it - Tweets Saved By @JohnLaTwC

Saved - October 24, 2023 at 8:16 AM
reSee.it AI Summary
I recently spoke at @MSFTBlueHat, discussing the valuable lessons and truths that incidents can teach defenders. Defense, often overshadowed by offense, has its own creative ideas. Foundational concepts for defenders include tracing attacker activity in logs, understanding attacks on multiple layers, and the importance of pivoting. Time-traveling through logs helps identify breaches, with certain techniques serving as detection bottlenecks. Building trust, addressing inter-team issues, prioritizing mental health, and maintaining work/life boundaries are crucial. Stay tuned for the video link! #MSFTBlueHat #cybersecurity

@JohnLaTwC - John Lambert

I spoke at @MSFTBlueHat last week. ➡️https://github.com/JohnLaTwC/Shared/blob/master/Presentations/2023-10-BluehatUS.pptx I will follow up with a link to the recording when it is posted. Some highlights from my talk below👇👇👇

File not found · JohnLaTwC/Shared Shared Blogs and Notebooks. Contribute to JohnLaTwC/Shared development by creating an account on GitHub. github.com

@JohnLaTwC - John Lambert

I talked about how incidents can teach powerful lessons and contain important truths for defenders.

@JohnLaTwC - John Lambert

I talked about while it is often romanced that offense has a richer toolset compared to the singular metaphor for defense ("the shield"). Defense has many creative ideas within it as well.

@JohnLaTwC - John Lambert

Some foundational concepts for defenders include: 1. Every contact leaves a trace...in a log 2. Defense involves the process of mapping attacker activity to its traces in logs 3. Attacks can take place on many logical layers 4. How essential pivoting is to navigating your data

@JohnLaTwC - John Lambert

I talked about the ability to find breaches by time-traveling through logs. Some attacker techniques may have fewer methods of expression (e.g. credential dumping, privileged group enumeration) and these serve as important detection "bottlenecks" in the kill chain.

@JohnLaTwC - John Lambert

I also talked about the importance of building trust as defenders and how it can be the fastest way to accomplish things.

@JohnLaTwC - John Lambert

Often our toughest problems at work are not technical, but rather inter-team issues. I gave some tips on dealing with these.

@JohnLaTwC - John Lambert

Finally, I talked about the importance of staying sane, focusing on your health, and having good work/life boundaries.

@JohnLaTwC - John Lambert

When the video for the talk is posted, I will link it here.

@JohnLaTwC - John Lambert

The audio 🎙️of this talk can be found at the @bluehat podcast: https://podcasts.apple.com/us/podcast/bluehat-oct-23-day-1-keynote-john-lambert/id1688087915?i=1000631758360

‎The BlueHat Podcast: BlueHat Oct 23 Day 1 Keynote: John Lambert on Apple Podcasts In this week’s special episode, we bring you the BlueHat Oct 23, day 1 keynote delivered by John Lambert, Microsoft Corporate Vice President and Security Fellow. In his BlueHat Oct day 1 keynote, John discusses the importance of incidents in the security field, strategies for finding security incide… podcasts.apple.com
View Full Interactive Feed