Ali-Al

Infosec, baking, lockpicking, Pathfinding, pranking mom

2023-04-27

@ktneely Automating on "garbage" introduces a ton of risk - you have to assume you're getting all the data and have perfect visibility before talking automation and 99% of orgs don't have that. They think they do, but they don't.

If you're automating alert responses, tune the alerts. If nobody's looking at it, why generate an alert? If you're automating information gathering, ask why your tools aren't giving you a whole picture and fix it. Automation *could* work in a static environment, but what org is ever static? If people have to constantly revise the automations, why not just do the work to begin with?

IR is not the place for automation bc you're 100% guaranteed to eventually miss something that will get you popped. Nobody wants to be on the hook for that but really, will insurance pay out on a breach that happened because automation obfuscated the attack before a human caught it? How many times will they do that before they start refusing?

This terrifies me because it's indicative that people are forging ahead with "automate ALL THE THINGS" without considering the risk generated by it, and implying that it frees up their humans for more interesting things when in reality it creates a new layer of labor around maintaining the automations. Worse yet, it creates a false sense of complete protection thinking automation catches more than humans do, which is pure vendor-speak and not true at all.

TL:DR - automation on bad datasets is a recipe for disaster, just fix your s**t and you don't need it.

2023-04-26

@ktneely These responses are terrifying to me.

2023-03-29

If corporations are people, does that mean they're generally the product of same-sex relationships?

2023-01-06

@varx @SwiftOnSecurity Really if we could just get a frame that's big enough to fit all the boxes in it, that would cover the daily roller coaster (in my world anyway lol)

2023-01-05

@SwiftOnSecurity Don't most SIEMs have a built-in system for dropping raw logs that are similar enough to an initial one? Just keep the timestamps if the content never changes so you know how many came in and when, problem solved?

2022-12-07

#InfosecJobAffirmations - I have a ton of these and will post them randomly

2022-11-14

@C0redump Hai! :ablobspin:​

2022-11-14

I'm excited that my first post on here is about #HackerSecretSanta2022 <3 I can't wait for this year's victim - err, recipient!!

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst