SOC Meets Cloud: What Breaks, What Changes, What to Do?

Detection Engineering and SOC Scalability Challenges (Part 2) [Medium Backup]

 This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.This post is our second installment in the “Threats into Detections — The DNA of Detection Engineering” series, where we explore the challenges of detection engineering in more detail — and where threat intelligence plays (and where some ... Read More
Build for Detection Engineering, and Alerting Will Improve (Part 3) [Medium Backup]

Build for Detection Engineering, and Alerting Will Improve (Part 3) [Medium Backup]

 This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.In this blog (#3 in the series), we will start to define and refine our detection engineering machinery to avoid the problems covered in Parts 1 and 2.Detection Engineering is Painful — and It Shouldn’t Be ... Read More

Focus Threat Intel Capabilities at Detection Engineering (Part 4) [Medium Backup 10/24/2023]

 This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.In this blog (#4 in the series), we will start to talk about the elephant in the room: how intel becomes detections (and, no, it is not trivial)Detection Engineering is Painful — and It Shouldn’t Be ... Read More
How to Banish Heroes from Your SOC? [Medium Backup 10/12/2023]

How to Banish Heroes from Your SOC? [Medium Backup 10/12/2023]

| | Medium Backup, SOC
 This blog was born from two parents: my never-finished blog on why relying on heroism in a Security Operations Center (SOC) is bad and Phil Venables “superb+” blog titles “Delivering Security at Scale: From Artisanal to Industrial.”BTW, what is heroism? Isn’t that a good thing? Well, an ancient SRE deck defines “IT heroism” as relying on “individuals ... Read More
Focus Threat Intel Capabilities at Detection Engineering (Part 4)

Focus Threat Intel Capabilities at Detection Engineering (Part 4)

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.In this blog (#4 in the series), we will start to talk about the elephant in the room: how intel becomes detections (and, no, it is not trivial)Detection Engineering is Painful — and It Shouldn’t ... Read More
How to Banish Heroes from Your SOC?

How to Banish Heroes from Your SOC?

This blog was born from two parents: my never-finished blog on why relying on heroism in a Security Operations Center (SOC) is bad and Phil Venables “superb+” blog titles “Delivering Security at Scale: From Artisanal to Industrial.”BTW, what is heroism? Isn’t that a good thing? Well, an ancient SRE deck ... Read More
Build for Detection Engineering, and Alerting Will Improve (Part 3)

Build for Detection Engineering, and Alerting Will Improve (Part 3)

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.In this blog (#3 in the series), we will start to define and refine our detection engineering machinery to avoid the problems covered in Parts 1 and 2.Detection Engineering is Painful — and It Shouldn’t ... Read More
Detection Engineering and SOC Scalability Challenges (Part 2)

Detection Engineering and SOC Scalability Challenges (Part 2)

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.This post is our second installment in the “Threats into Detections — The DNA of Detection Engineering” series, where we explore the challenges of detection engineering in more detail — and where threat intelligence plays (and ... Read More
New Paper: “Securing AI: Similar or Different?“

New Paper: “Securing AI: Similar or Different?“

As you may have noticed, we have released a new paper on securing AI. I want to share a few additional things here on top our official launch blog.src: http://bit.ly/ociso-ai1-podFor a few years (so, yes, I did start before the ChatGPT launch, if you have to ask…), I’ve been a little ... Read More
Detection Engineering is Painful — and It Shouldn’t Be (Part 1)

Detection Engineering is Painful — and It Shouldn’t Be (Part 1)

| | detection-engineering
Detection Engineering is Painful — and It Shouldn’t Be (Part 1)This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator.This post is our first installment in the “Threats into Detections — The DNA of Detection Engineering” series, where we explore opportunities and shortcomings in the brand ... Read More