Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. achievement unlocked:

achievement unlocked:

Scheduled Pinned Locked Moved Uncategorized
8 Posts 4 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.social
    wrote last edited by
    #1

    achievement unlocked:

    first, formal writeup to a customer where i have to cite another vendor they are using sending them ai slop in honeypot and edr alerts.

    one thought a portscan was "an attacker conducting lateral movement"

    then another thought dropping rubeus.exe onto a laptop, and having it immediately caught and deleted qualified as "a ransomware event"

    this is just bananas.
    its borderline fraud

    viss@mastodon.socialV winterknight1337@infosec.exchangeW 2 Replies Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      achievement unlocked:

      first, formal writeup to a customer where i have to cite another vendor they are using sending them ai slop in honeypot and edr alerts.

      one thought a portscan was "an attacker conducting lateral movement"

      then another thought dropping rubeus.exe onto a laptop, and having it immediately caught and deleted qualified as "a ransomware event"

      this is just bananas.
      its borderline fraud

      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote last edited by
      #2

      like, if you work at a company that sends ai slop to people as security alerts, you should strongly consider quitting on ethical grounds

      viss@mastodon.socialV 1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        like, if you work at a company that sends ai slop to people as security alerts, you should strongly consider quitting on ethical grounds

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote last edited by
        #3

        like, imagine getting the page and setting up an IR bridge and being the incident commander at 3am on a sunday morning and it turns out 'the honeypot vendor thought a portscan was a ransomware event and the portscan was a contractor or a junior devops guy running the spiceworks demo on a laptop or running an nmap'

        youre gonna be pissed.
        so are the people cutting the checks to that vendor

        theorangetheme@en.osm.townT winterknight1337@infosec.exchangeW 2 Replies Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          like, imagine getting the page and setting up an IR bridge and being the incident commander at 3am on a sunday morning and it turns out 'the honeypot vendor thought a portscan was a ransomware event and the portscan was a contractor or a junior devops guy running the spiceworks demo on a laptop or running an nmap'

          youre gonna be pissed.
          so are the people cutting the checks to that vendor

          theorangetheme@en.osm.townT This user is from outside of this forum
          theorangetheme@en.osm.townT This user is from outside of this forum
          theorangetheme@en.osm.town
          wrote last edited by
          #4

          @Viss That IR bridge would become a struggle session real fast, holy hell.

          1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            achievement unlocked:

            first, formal writeup to a customer where i have to cite another vendor they are using sending them ai slop in honeypot and edr alerts.

            one thought a portscan was "an attacker conducting lateral movement"

            then another thought dropping rubeus.exe onto a laptop, and having it immediately caught and deleted qualified as "a ransomware event"

            this is just bananas.
            its borderline fraud

            winterknight1337@infosec.exchangeW This user is from outside of this forum
            winterknight1337@infosec.exchangeW This user is from outside of this forum
            winterknight1337@infosec.exchange
            wrote last edited by
            #5

            @Viss wat

            winterknight1337@infosec.exchangeW 1 Reply Last reply
            0
            • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

              @Viss wat

              winterknight1337@infosec.exchangeW This user is from outside of this forum
              winterknight1337@infosec.exchangeW This user is from outside of this forum
              winterknight1337@infosec.exchange
              wrote last edited by
              #6

              @Viss the rubeus thing is actually fucking wild.

              1 Reply Last reply
              0
              • viss@mastodon.socialV viss@mastodon.social

                like, imagine getting the page and setting up an IR bridge and being the incident commander at 3am on a sunday morning and it turns out 'the honeypot vendor thought a portscan was a ransomware event and the portscan was a contractor or a junior devops guy running the spiceworks demo on a laptop or running an nmap'

                youre gonna be pissed.
                so are the people cutting the checks to that vendor

                winterknight1337@infosec.exchangeW This user is from outside of this forum
                winterknight1337@infosec.exchangeW This user is from outside of this forum
                winterknight1337@infosec.exchange
                wrote last edited by
                #7

                @Viss I’m very curious on which vendor this is 👀

                B 1 Reply Last reply
                0
                • winterknight1337@infosec.exchangeW winterknight1337@infosec.exchange

                  @Viss I’m very curious on which vendor this is 👀

                  B This user is from outside of this forum
                  B This user is from outside of this forum
                  bakachu@infosec.exchange
                  wrote last edited by
                  #8

                  @winterknight1337 @Viss the copilot summaries in defender for endpoint are exactly that bad...

                  1 Reply Last reply
                  1
                  0
                  • R relay@relay.infosec.exchange shared this topic
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups