| http | https://sroberts.io |
| gh | https://github.com/sroberts |
| book | https://www.oreilly.com/library/view/intelligence-driven-incident-response/9781098120672/ |
| http | https://sroberts.io |
| gh | https://github.com/sroberts |
| book | https://www.oreilly.com/library/view/intelligence-driven-incident-response/9781098120672/ |
Ever tried combining Large Language Models with Structured Analytic Techniques? It’s like teaching an AI to think like an intelligence analyst—minus the SCIF and crippling paranoia.
Dive into the experiment: https://sroberts.io/posts/llm-sats-ftw/
Unless you’ve spent the last 5 years asleep you know that every team, business, and industry is being turned upside down by AI. Every startup is trying to create the newest AI offering, every tech giant is trying to add LLM functionality everywhere, and every business is trying to replace employees with agents. But what does this mean for intelligence analysts? How can we use LLMs to help us with our work? And what are the limitations? Can we overcome them? Or are we just going to end up with a bunch of over hyped tools that don’t really help us at all?
Had my first serious presentation back after a few years hiatus. Not my best, not my worst, but glad to get back into it. My own after action:
- I worried a lot about content length, first that I was going to be short. Definitely caused me to drag a bit early.
- I was wrong, and had a great amount of content, but mid way through realized I was behind (especially with the time clock ticking down) and started rushing. I tripped over my words more than I should have.
- After lunch remains a tough spot, though I'd rather after it than before.
- I didn't inject enough humor. My two jokes, one at the start and one mid way through, both hit well though.
- I forgot to really call out takeaways. On one hand I was already tight on time, but that was a big miss.
- I didn't practice enough. While I haven't been speaking in the presentation sense much lately I have been teaching, which allows a lot of extemporaneous speaking comfort. That doesn't translate as well as I'd have hoped.
- I missed speaking and it was very enjoyable to be back up there.
If you haven't been @mitreattack is a fantastic conference I can't recommend enough. Definitely in my top three with CyberwarCon and @sansforensics CTI Summit. I'll :100: be back!

Using a well-conceived incident response plan in the aftermath of an online security breach enables your team to identify attackers and learn how they operate. But only when you... - Selection from Intelligence-Driven Incident Response, 2nd Edition [Book]
Hey there, hunters! The next blog in our #PEAK threat hunting framework series is out: "Baseline Hunting with the PEAK Framework". Learn how to profile normal behavior in your network and find deviations that might indicate malicious activity!
https://www.splunk.com/en_us/blog/security/peak-baseline-hunting.html