#FIRSTCON23

2023-10-12

Long and awaited...the #FIRSTCON23 @firstdotorg TLP:CLEAR recordings have been published to our YouTube! Check them out here youtube.com/c/firstdotorg

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-07-21

Slightly behind on announcements 📢

#FIRSTCON23 may be over, but we still have content to share! Tune in this #FIRSTFriday for Diamond sponsor, @Cisco’s First Time Attendee guest Blog article: ow.ly/2ROl50P8IvK + @Cisco’s CSIRT CTO, Vinay Bansal’s #FIRSTImpressions interview here: media.first.org/podcasts/FIRST

FIRST Impressions podcast logo and episode name
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-07-05

Been editing a bunch of podcasts from #FIRSTCON23. Great collection of smart people… Can't wait for the podcasts to be released.

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-07-03

Did you miss #FIRSTCON23? Have no fear; the #FIRSTImpressions podcast is here! Check out the newest episode to learn about the critical role #PSIRT plays in Customer Trust, Adoption, and Renewal from con speakers, Kevin Hagopian and Emer O’Neill. ow.ly/IXa950OZIQB

First Podcast banner
2023-06-23

#DNS #zip TLD fun facts.

There are about 14,000 names in the .zip zone.

un.zip is not in the zone, but it is reserved and you can't register it.

bidenleak.zip and trumpleak.zip were both registered on May 13 seemingly at the same time by the same registrant, and are currently parked.

There are dozens of names that have "install" in the first label, those might be good ones for a rainy day analysis.

dataplane.zip has a secret message if you can find it (some did at #FIRSTCON23).

Some .zip names aren't cheap. For example, boston.zip is currently available, but it'll cost ya.

Daniel AJ Sokolovnewstik@social.heise.de
2023-06-19

#Canada's top #cybercrime cop wanted to talk about common misunderstandings of #police work, and how he hopes to limit the impact of cybercrime in a #holistic way. So we talked.

Read at @heiseonline in German:

heise.de/hintergrund/Kanadas-o

#FIRSTcon23

Daniel AJ Sokolovnewstik@social.heise.de
2023-06-16

Welche digitalen Bedrohungen gibt es in einem Land, in dem mit #Ransomware und #Crypto #Betrug nichts zu holen ist?

Ich hatte die Gelegenheit, mit dem Leiter des Malawi #CERT zu sprechen. #Malawi ist eines der ärmsten Länder der Welt, dennoch setzt die Regierung auf Digitalisierung. Allein, es gibt keine Fachkräfte für #IKT #Sicherheit.

Täter zu verhaften ist oft unmöglich - denn sie sitzen bereits in ganz furchtbaren Gefängnissen.

heise.de/hintergrund/IT-Sicher

#FIRSTcon23 #FIRST #Armut #Afrika

Dave Dugal đź”’:mastodon: :donor:vipergeek@infosec.exchange
2023-06-09

The Forum of Incident Response and Security Teams (#FIRST) is proud to announce the official release of #CVSS v4.0 #ThePublicPreview. The latest information on CVSS v4.0 can be found at first.org/cvss/v4-0/ #FIRSTCON23

CVSS logo
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

"Prevention without pursuit is toothless, but
pursuit without prevention is endless"

#FIRSTCON23

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

Final presentation of #FIRSTCON23.

Chris Lynam, Director General of the National Cybercrime Coordination Centre (NC3)

The integrated role of law enforcement in cyber is critical. We are all responsible for reducing the harm and effects of Cybercrime on the public.

Facing highly motivated, unscrupulous, and adaptive human advisaries
2023-06-09

I have seen a lot of infosec.exchange links in #FIRSTCON23 presentations, almost no Twitter

Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

Scope of Cyber Hygiene Hunting
"Pyramid of Gain for Cyber Hygiene Hunting"

#FIRSTCON23

Scope of Cyber Hygiene Hunting "Pyramid of Gain for Cyber Hygiene Hunting"
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

Cyber Hygiene Hunting - A continuous / proactive approach to identification of risks that may cause future intrusion.

IoC (Indicator of compromise) - past looking vs EoC (Enabler of compromise) - future looking

#FIRSTCON23

Cyber Hygiene Hunting title slideBe adaptive strategy slideIOC vs EOC
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

SBOM is only the beginning. Product Bill of Materials is the next step.

#FIRSTCON23

Product Bill of Materials
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

When you go to RFP, you should be asking these questions to get confirmation the vendor is doing the right thing.

#FIRSTCON23

Things to ask your vendorOperational plans
AP on ComputerScienceFuturesCompSciFutures@infosec.exchange
2023-06-09

@ChrisJohnRiley There's actually 12 pillars, if you want to talk about necessary, sufficient & complete security.

They arrange such that you can't have any consequent pillar without it's antecedents.

See dx.doi.org/10.13140/RG.2.2.126

Perhaps let CMU SEI know :)

#FIRSTCON23 #CyberAttack #InfoSec #CyberSec

The 12 Pillars of Information Security
Chris John Riley :unverified:ChrisJohnRiley@infosec.exchange
2023-06-09

Starting off the last day if the conference with 'The four pillars of Cybersecurity" by Laurie Tyzenhaus (CERT CC)

#FIRSTCON23

The four pillars of Cybersecurity intro slide
:sm64_d: :sm64_l: :sm64_i: :sm64_l: :sm64_j: :sm64_a:dlilja@infosec.exchange
2023-06-08

Big shoutout to everyone who attended my lightning talk; “My Insta Turned Into a Honeypot”, at #firstcon23. I had a blast running through 105 slides in 5 minutes. Thanks for giving me a lot of energy! 🙏🏻

#scammers #honeypot #instagram #firstdotcom #montreal
@Instagram @firstdotorg

Alexandre Dulaunoyadulau@infosec.exchange
2023-06-08

A new open source tool to check the integrity of an iPhone without jailbreaking it. Great work from @ddurvaux @aaronkaplan and Emilien.

#DFIR #FIRSTCON23

github.com/EC-DIGIT-CSIRC/sysd

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst