Scott J Roberts

543 Followers
162 Following
122 Posts
If you’re releasing a TLP Amber report that’s nothing but a rehash of public reporting you’re using TLP incorrectly.

Ever tried combining Large Language Models with Structured Analytic Techniques? It’s like teaching an AI to think like an intelligence analyst—minus the SCIF and crippling paranoia.

Dive into the experiment: https://sroberts.io/posts/llm-sats-ftw/

#LLM #StructuredAnalysis #IntelligenceAnalysis

LLM SATs FTW

Unless you’ve spent the last 5 years asleep you know that every team, business, and industry is being turned upside down by AI. Every startup is trying to create the newest AI offering, every tech giant is trying to add LLM functionality everywhere, and every business is trying to replace employees with agents. But what does this mean for intelligence analysts? How can we use LLMs to help us with our work? And what are the limitations? Can we overcome them? Or are we just going to end up with a bunch of over hyped tools that don’t really help us at all?

@sroberts
One of the nicest things about my transition to academia is the time to read, often reading stuff I'd argue I should have been reading while running threat research.
Also shout out to @pdxbek and @sroberts for this incredible book on #threatintel and #incidentresponse and to @likethecoins for the recommendation in her Threat Intelligence guide.

Had my first serious presentation back after a few years hiatus. Not my best, not my worst, but glad to get back into it. My own after action:

- I worried a lot about content length, first that I was going to be short. Definitely caused me to drag a bit early.
- I was wrong, and had a great amount of content, but mid way through realized I was behind (especially with the time clock ticking down) and started rushing. I tripped over my words more than I should have.
- After lunch remains a tough spot, though I'd rather after it than before.
- I didn't inject enough humor. My two jokes, one at the start and one mid way through, both hit well though.
- I forgot to really call out takeaways. On one hand I was already tight on time, but that was a big miss.
- I didn't practice enough. While I haven't been speaking in the presentation sense much lately I have been teaching, which allows a lot of extemporaneous speaking comfort. That doesn't translate as well as I'd have hoped.
- I missed speaking and it was very enjoyable to be back up there.

If you haven't been @mitreattack is a fantastic conference I can't recommend enough. Definitely in my top three with CyberwarCon and @sansforensics CTI Summit. I'll :100: be back!

So I'm trying to come back into the social media world, but I'm not sure where we're at anymore. Mastodon seems to just be mirrors, Threads seems to be dead, X seems to be the same people shouting louder than ever without everyone else (plus rampant disinformation). Did the security community just go underground?
If you’re at @blackhat come visit @pdxbek and I at the @oreilly booth (2905D) at noon to get a signed copy of Intelligence Driven Incident Response 2nd Edition! If you’re not at BlackHat and get a copy I’ll owe you a signature. https://www.oreilly.com/library/view/intelligence-driven-incident-response/9781098120672/
Intelligence-Driven Incident Response, 2nd Edition

Using a well-conceived incident response plan in the aftermath of an online security breach enables your team to identify attackers and learn how they operate. But only when you... - Selection from Intelligence-Driven Incident Response, 2nd Edition [Book]

O’Reilly Online Learning

Hey there, hunters! The next blog in our #PEAK threat hunting framework series is out: "Baseline Hunting with the PEAK Framework". Learn how to profile normal behavior in your network and find deviations that might indicate malicious activity!

https://www.splunk.com/en_us/blog/security/peak-baseline-hunting.html

#SURGe #ThreatHunting

Baseline Hunting with the PEAK Framework

Splunker David Bianco provides an in-depth look at baseline hunts, also known as Exploratory Data Analysis (EDA) hunts.

Splunk-Blogs
Crap like this makes me hate the Internet…
Can someone explain to me why Google's CTF doesn't allow Quebec?!