Chris John Riley :unverified:

I'm just this guy, you know!

- Views my own 😇
- ex-Staff Security dino @ Google 🦕
- Purveyor of fine whisky 🥃, hard mixes 🎧🎚️, & fresh bull 💩
- Zurich 🇨🇭 / Valencia 🇪🇸
- On the path to FI/RE

DJ Mixes mixcloud.com/c22dnb #dnb #DrumAndBass

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

Attending #FIRSTCON25?
Hiring for remote security roles that are unique, flexible, and interesting?
Hit me up… I'll be here all week 👋

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

Prioritize your scripts and detections. If you're not a Microsoft shop, do you care about sqlcmd.exe execution?

#FIRSTCON25

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

"Be careful you don't overfit detection logic"

Creating a rule that only detects the test case. This brings up memories of rules that used to detect script injection by looking for "<script>" but then failed to detect simple variants like "<scr'+'ipt>".

#FIRSTCON25

Building new rules slide:

Be careful you don't overfit detection logic

Good for detecting the test, but not be great for detecting an adversary

Important to balance the precision to the intent or behavior

Any detection can fall victim to this
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

The "Trough or Disillusionment" #FIRSTCON25

Mapping Atomic Red Team Tests & Rules — Some techniques align, many don't.

H/T @stonerpsu

Trough or Disillusionment slide:

Sharpening my Atomic Red Team efforts & converting SIGMA rules

Mapping Atomic Red Team Tests & Rules

Some techniques align, many don't

Identify overlaps in coverage - Can we tag the data to the rule/detection?

Possible misses in coverage (no test to detect) - Need to build our own

Need to get a feel for what detections have never fired

Scripts run a hundred tests, how do we reconcile all the tests to all the rules

#FIRSTCON25
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

"Prevention will fail somehow somewhere. My goal is to ensure detections are always in place and usable."

#FIRSTCON25

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

Accepting that we're all open to bias is the biggest challenge.

Simply being aware of bias doesn't mean that we're immune, and accepting that bias isn't just something that others are vulnerable to is critical.

#FIRSTCON25

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

Another interesting read — "Normalization of deviance"

"Normalization of deviance is a concept that describes the gradual process by which a behavior or practice that deviates from the established norm or standard becomes accepted as the new normal, especially within an organization."

Example: Challenger disaster

#FIRSTCON25

Normalization of deviance
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

First time hearing about the Abilene paradox. Very interesting 🤔

"The Abilene Paradox describes a situation where a group of people collectively decides on a course of action that is counter to the preferences of most, if not all, of the individuals in the group."

#FIRSTCON25

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-23

Kick-starting #FIRSTCON25 with a deep dive into bias in forensics and incident response.

Monday Keynote Address: Unpacking the Human Factor: Navigating Individual, Socio-Technical, and Systemic Challenges in Incident Investigations
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-21

@krypt3ia What they lack in size, they make up for in violence

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-21

@krypt3ia Space dog is unhappy

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-21
Chris John Riley :unverified: boosted:
2025-06-20

What happens when a major city suffers a data breach and the world is watching? #FIRSTCON25 speaker Matias Mesiä (NCSC-FI) shares insights from the 2024 Helsinki incident with the #FIRSTImpressions Podcast. 🚨 media.first.org/podcasts/FIRST 🔗

Chris John Riley :unverified: boosted:
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-19

@Viss We should all feel free to suck at things extensively in personal and professional life… I hope we both have a chance.

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-19

@Viss You're right!!! I've sucked at this for long enough. I deserve to suck at something new for a while 🤷‍♂️

Chris John Riley :unverified: boosted:
VissViss
2025-06-19
Chris John Riley :unverified: boosted:
Oblique Strategiesoblique_strategies@mas.to
2025-06-19
A black-and-white photo of an Oblique Strategy card. The card reads: 'Be dirty'.
Chris John Riley :unverified: boosted:
2025-06-19

Hungarian police ban Budapest's Pride march, but its mayor vows to hold it anyway.

Hungarian police on Thursday banned the country's main Pride march from taking place in Budapest on 28 June, citing a law against the promotion of homosexuality to minors.

The capital's mayor Gergely Karácsony vowed to hold it despite the interdiction.

mediafaro.org/article/20250619

#Hungary #Pride #Budapest #LGBTQ #GergelyKaracsony

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2025-06-19

@mattblaze It's only bullshit if it comes from the DC area of the US… otherwise it's just sparkling bovine poop 💩

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst