#sans

4 posts · Last used 10d

Back to Timeline
Michael Koerfer @OT_MacDonald@infosec.exchange · Aug 04, 2026
When asked when I’ll be attending #BlackHat, #DEFCON, #BSidesLV, or a #SANS event, my answer is: probably never. It’s not for lack of desire, quite the opposite; I would love to attend. The simple reason is that I am the sole breadwinner supporting my family, and I finance these trips and conferences, as well as my lab and research, entirely out of my own pocket, all while having to take vacation time to attend. Consequently, I have to choose very carefully which events to attend and plan them well in advance. Spontaneous trips are rarely an option for me. Of course, I’m aware of the argument that my company benefits from this, too. That is true, just as they benefit from many of my other activities. However, there is no willingness on their part to contribute financially or organizationally. Instead, there are usually "good reasons" why it isn't possible. That is the reality. Nevertheless, I continue to invest in my #professionaldevelopment because it matters to me.
0
0
0
hasamba @hasamba@infosec.exchange · Jul 30, 2026

🎯 AI-run attacks and SOC detection gaps

The article raises a practical question from a post-incident debrief: "There were alerts. They did not rise to the right level. How does the SOC miss this?" The gap isn't in signal generation but in alert severity and escalation logic.

The core problem

AI-driven attacks operate across multiple paths simultaneously, with no single event being critical enough to trigger paging. Traditional alert rules, tuned for single high-severity events, miss the aggregate pattern. Alerts fire but stay below the threshold that would wake someone at 2 AM on a Saturday.

What "ready" looks like

Three concrete detection strategies are proposed:

  1. Alert-severity rules for slow, multi-path attacks: Rules that aggregate low-severity signals across paths, so that no single event needs to be critical for the on-call person to get paged. The trigger is the pattern, not the individual event.

  2. Baseline of your own automation: Establish what your legitimate automation looks like (scheduled scripts, service accounts, API calls) so that hostile automation becomes distinguishable. Without a baseline, an AI agent running reconnaissance at machine speed blends into normal noise.

  3. Deception seeded throughout the environment: Canary files, honeytokens, fake shares. A fast, indiscriminate AI agent trips these because it doesn't have the context to avoid them. A careful human adversary would walk past them.

Relevant SANS courses • SEC555: Detection Engineering and SIEM Analytics (GIAC GCDA) • SEC541: Cloud Security Threat Detection (GIAC GCTD) • SEC599: Defeating Advanced Adversaries: Purple Team Tactics and Kill Chain Defenses (GIAC GDAT)

Analysis

The article doesn't present a specific incident or IoCs. It's a conceptual framework for detection engineering against AI-driven threats. The core insight is that detection logic built for human-speed, single-path attacks won't catch AI agents operating across multiple vectors simultaneously at machine speed.

The deception approach is the most immediately actionable. Canary-based detection doesn't require new analytics pipelines, it just requires seeding artifacts that only a non-human actor would touch.

The automation baseline concept is sound but operationally harder. Most organizations don't have a clean inventory of what their own automation does, making it difficult to establish a useful baseline.

The SANS course references suggest this content is tied to training curriculum rather than independent research. The framework itself is preliminary, no empirical validation is provided.

🔹 AI #DetectionEngineering #SOC #SANS #Deception

🔗 Source: https://www.sans.org/go/readiness-for-ai-automated-attacks?utm_medium=Organic_Social&utm_source=Twitter&utm_content=Rob_T_Lee&utm_campaign=Critical_Advisory_Urgent_Sandbox_Guardrails&utm_rdetail=Global&utm_goal=Community_Awareness&utm_type=Thought_Leadership

0
0
0
Cthonyxa @cthonyxa@mastodon.art · Jun 30, 2026
Meant to post this yesterday but was dealing with some nasty fatigue. Anyway, I did another picture of Dream Sans with his current outfit this time! I think it came out well? #art #traditionalart #fanart #sketch #undertale #sans #dreamsans #mastoArt
5
0
1
Tinker ☀️ @tinker@infosec.exchange · Apr 23, 2026
Boosted by Greg Bell @ferrix@mastodon.online
Ummm... Is SANS training ICE? https://sam.gov/workspace/contract/opp/99f8bdc298c34f06bcac9bd7e39b1bca/view Edit to add: SANS is training ICE how to pull information off of harddrives, etc. FOR498: Digital Acquisition and Rapid Triage "Course Overview: A digital forensic acquisition training course, FOR498 provides the skills to identify the many and varied data storage mediums in use today, and how to collect and preserve this data in a forensically sound manner despite how and where it may be stored. This forensics data collection course covers digital acquisition from computers, portable devices, networks, and the cloud, and teaches rapid triage—the art and science of identifying and starting to extract actionable intelligence from a hard drive in 90 minutes or less." This training will directly hurt people. #sans #ice #infosec
68
33
116

You've seen all posts