David J. Bianco (He/Him)

@DavidJBianco@infosec.exchange
1.5K Followers
270 Following
457 Posts
Threat Hunting, Cyber Threat Intelligence, incident detection and response. SANS Certified Instructor. Special interest in helping newbies get into the field. He/Him
Bloghttps://detect-respond.blogspot.com
Twitter@DavidJBianco
Twittodonhttps://twittodon.com/share.php?t=DavidJBianco&m=DavidJBianco@infosec.exchange
Fave ShapePyramid
Splunk's #SURGe research team is now Cisco Foundation AI's SURGe security team, and I couldn't be more excited. We've been researching #AI's impact on #cybersecurity for years now, and how teams can leverage it to improve their operations. Now our team's extensive cybersecurity experience is paired with Foundation AI's world-class AI expertise. I'm really looking forward to what we can do together.
Even Claude can't get the 'jq' syntax right. How are us mortals supposed to do it?

The video for my talk last month at the #Honeynet Project Workshop is now available.

"Hi Fidelity != Hi Effort: Meet DECEIVE, the AI-backed SSH Honeypot"

Thanks to the workshop organizers for having me!

https://www.youtube.com/watch?v=uxbzGcIegVU&t=7052s

We recently celebrated 16 years of the Security Onion project and today we celebrate 11 years of Security Onion Solutions as a company! Thanks to our customers and community for your support throughout the years! We've come a long way, but the best is yet to come!

The EU wants to stop feeding your DNS queries to Silicon Valley.

DNS4EU is the European Commission’s attempt to build a sovereign DNS resolver infrastructure that doesn’t route all your web lookups through the likes of Google, or Cloudflare.

DNS4EU aims to bring DNS resolution under EU oversight and privacy rules.

So, if you want 🇪🇺-backed ad-blocking and child protection, you may want to give it a try.

Check out DNS4EU here: https://www.joindns4.eu/for-public

"Well, better get back to work. This code ain't gonna write itself."

Guess I have to stop using that one now. #AI

Looking for a new gig as a #cybersecurity researcher? Want to figure out new ways to achieve better security outcomes then tell everyone how? Check out our opening on the #Splunk #SURGe team!

https://www.splunk.com/en_us/careers/jobs/sr-security-strategist-surge-32798.html

Sr. Security Strategist, SURGe | Splunk

Splunk
Windows is getting support for the ‘USB-C of AI apps’

Microsoft is integrating MCP support directly into Windows. It’s part of a big push to build an AI platform for Windows AI Foundry.

The Verge

Speaking of upcoming appearances, I'll be talking about DECEIVE, my LLM-based SSH honeypot at the #Honeynet Project's workshop in Prague next month. If you're there, come say hi. As usual, I'll have #PyramidOfPain stickers and buttons.

https://prague2025.honeynet.org/

For more about DECEIVE:
https://www.splunk.com/en_us/blog/security/deceive-ai-honeypot-concept.html

2025 Honeynet Project Workshop – Prague, Czech Republic

If you're looking for quality network forensics training, there's still time to register for my upcoming class at SANS Cyber Defense Canberra June 23 - 28. If you can't make it in person, it'll be streamed LiveOnline too.

I hope to see some of you there!

https://www.sans.org/cyber-security-training-events/cyber-defence-australia-2025/

SANS Cyber Defence Canberra 2025 | SANS Institute

Achieve the expertise you need to succeed in days, not months. Immerse yourself in a week of elite training designed for all skill-levels at SANS Cyber Defence Canberra 2025. From hands-on labs to cutting-edge techniques taught by industry-leading instructors, you'll gain the skills to excel and the certifications to prove it.