Diego Perez

4 Followers
9 Following
28 Posts

✨ Parsing Threat Intel reports with LLM is fun and opens up huge possibilities. I've been doing this for quite a while and I think it's time to give it some better structure.

So far, LlamaIndex is the best package for this, though LangChain is good too. Gemini 1.5 Pro is the most comprehensive one, whilst GPT4o Mini is the most efficient in terms of speed and information returned. Ollama3.1 8B and 3.2 3B cannot handle complex JSON structures.

An example parsing an article from the DFIRReport

🚀 From Intel to Impact 🚀

💡 What if your cybersecurity data pipeline functioned like a Git repository, with each team acting as a branch, merging their insights and actions into a "main" pipeline to drive real-world impact?

Article: https://quasarops.com/from-intel-to-impact/

From Intel to Impact

What if your cybersecurity data pipeline functioned like a Git repository, with each team acting as a branch, merging their insights and actions into a "main" pipeline to drive real-world impact? Join me on this "Git-inspired" approach to scalable cyber operations.

Quasarops

🤖🧙 MEDITATIONS OF A CYBERSCOUT 12

Uncertainty is the awareness of our own ignorance. Humility is not feeling ashamed of it. Stupidity is consistently failing to be self-aware of it. Vanity is underestimating it. Stubbornness is negating it. Fear is at the root of it all.

🤖🧙 MEDITATIONS OF A CYBERSCOUT 09

A TTP is a capability. It is not a material attack and it's only half the picture. Ask yourself, can this impact my organization? A threat vector is nothing without a vulnerability in your attack surface.

#ttp #attacksurface #threatmodelling

🤖🧙 MEDITATIONS OF A CYBERSCOUT 08

The past and the stars,
a constant glimmer,
everywhere you go.

🤖🧙 MEDITATIONS OF A CYBERSCOUT 07

There is no ML algorithm or statistical shortcut for the rich deep-learning network that is your body. Some experiences can only be lived at the scale of human life. Slow down. Be present.

🤖🧙 MEDITATIONS OF A CYBERSCOUT 06

Simplification is lower resolution complexity that achieves good enough outcomes with less overall effort. This comes at a cost. Simplicity can be fragile. Its sustainability depends heavily on stable environmental conditions that are hidden by the simpler interface. You need higher effort investment elsewhere in the system or lucky "stable eras" to maintain dynamic equilibrium.

#complexity #api #explorationpatterns

🖋️🤖🧙 MEDITATIONS OF A CYBERSCOUT 05 🧙🤖🖋️

Be busy, but not too busy. When you are too busy, you are not available. Available means curious wondering. Curious wondering leads to open roads and refreshed mental states. If you can do it, don't let busy get in the way of wonder.

🛠️💡 HOW TO MASTER YOUR CRAFT 10

Don't underestimate the power of team morale.

🛠️💡 HOW TO MASTER YOUR CRAFT 09

Technical Debt means you have a "quantity over quality" problem.