Infosec and Data Enthusiast. Lecturer. Course Author. Coffee Nerd. He/Him.

Joined October 2014
80 Photos and videos
Pinned Tweet
I'm super happy and grateful to present you a new course I created together with the legendary @chrissanders88: Splunk for Security Analysts. I still can't believe it, but it just launched and I hope people will enjoy it 🀞
I’m excited to launch our latest course, Splunk for Security Analysts. ⛏️ You can read more about the online, on-demand Splunk for Security Analysts course and register now at networkdefense.co/courses/sp….
4
2
23
5,265
Thanks to @QuinnyPig's newsletter I stumbled upon this gem: Instead of providing a Sigma rule to copy/paste or download, AWS (or its AI) decided to include step by step instructions on what values to put in what fields: aws.amazon.com/security/secu…
47
I miss Audiogalaxy.
i miss napster
60
Regular Obsession retweeted
23 Sep 2025
Want to explore the Internet through a retro-futuristic version of Shodan? We've just updated the Shodan 2000 website: 2000.shodan.io/
6
41
257
22,906
I don't know many CISOs, but judging by the endless stream of "CISO guides" vendors keep cranking out, apparently the industry thinks they're all winging it.
32
Who says I can't be all 3?
38
To the person who decided that certificates in /usr/local/share/ca-certificates have to have a .crt file extension: Please be aware, that I'm not a huge fan of your decisions.
40
Today's reason to raise an eyebrow: Your document includes the phrase "Data is the new oil"
45
What's a good way to measure/communicate detection coverage? And no, not ATT&CK πŸ˜…
51
Interesting thought by @jack_naglieri that AI may replace (or enhance?) detection rule conversion currently done e.g. with @sigma_hqπŸ€” @cyb3rops @nas_bench are you thinking about / looking into this? Curious to get your take on it.
2
3
1,050
At least once the 90s aren't calling @anton_chuvakin, right? 😁
1
1
88
Dragonball detection engineering: When your goal is to get over 9000.
34
Regular Obsession retweeted
Replying to @chrissanders88
@chrissanders88 DFIR Course Investigative Theory is by far the best course I've ever recommended to teach this critical skill. chrissanders.org/training/in…
2
2
441
What's your take on alert scoring? High/medium/low vs. 0 - 100 vs. record/notification/page? Static per rule vs. influenced by subject or other attribute (e.g. if user == admin: score ) Communicated attribute: Severity vs. urgency vs. confidence...? One of them, a combo?
3
4
462
Even new portals still come up with a UX like this around passwords: * Password complexity requirements πŸ‘Ž * You ban (only) these 2 words? πŸ‘Ž * If you block certain special characters it seems you don't know much about encoding/escaping πŸ‘Ž * Red check marks for passed items πŸ™ˆ
44
Regular Obsession retweeted
29 Dec 2024
445
58,934
264,659
8,217,196
Recruiters doing memes on LinkedIn hurts so much, it should be a felony.
45
Regular Obsession retweeted
AND courses on sale tomorrow 😊
1
5
23
2,191
Me when my phone asks me for the name of the person in the selfies

ALT GIF of Bernard Lowe in Westworld saying: That doesn't look like anything to me

34