Post #4069849
2026-07-24 18:42 UTC
@Xavier@infosec.exchange To be frank, that sounds like missing telemetry in both cases. You shouldn't be guessing about follow-on behavior. And again, with that telemetry, you're focused on behavior and not who might have done it.
Replies (1)
-
@Xavier@infosec.exchange 2026-07-24 19:16
@mttaggart@infosec.exchange Of course, because it takes a while to get the full picture. Once we have indicators that we're dealing with SS or similar active threat, then we responding accordingly (all hands on deck again). But most of the time its not, so we don't. The answer to original question, knowing the threat class of the threat actor helps us not have to pull the fire alarm every time.