26 Followers
58 Following
66 Posts

Husband of an amazing wife, father of six, Catholic, Principal Technical Specialist for Azure Infrastructure & Security @ MSFT

I like running, biking, Jiu-Jitsu, video games, brewing and consuming beer, and whiskey.

I wanted to take a few moments and apologize to many of my former students.

In the past I said the industry needs people who look at security as a vocation and an avocation.

I was wrong.

Have a life outside of this industry.

Have hobbies that have nothing to do with your computer.

Get outside.

The problems of the industry are not problems of people not working hard enough.

They are not problems of people not being "hard core" enough.

They are problems of education and resource prioritization.

I was wrong.

I am sorry.

Stop breaking yourself on rocks for people who don't really care if you break yourself on rocks.

I like this kind of Humor.
Don’t forget to increment the year in your password!
No survival instincts in the city...

There’s been a lot of discussion about a rule we recently instituted regarding security testing on the infosec.exchange instance. I understand the value or pen testing as much or more than most people, and I’m fully cognizant that pen tests are happening all the time and I’m not getting the report. I get it. But there are now 28,000 people using this service to communicate. I know there are vulnerabilities waiting to be discovered. Finding blog post fodder by fuzzing instances that are already running hot due to explosive growth is not super helpful. But at the same time, I WANT that testing to happen.

As a result, I am going to set up two instances tomorrow that only federate with each other. This is where I’d prefer legitimate security testing be performed. I’ll also be using it as the QA environment to test new updates and settings prior to deploying to the production instance. I’ll moderate signups because I don’t want it accidentally becoming fediverse 2.0 in the ongoing rush for the doors at twitter, but will accept anyone who wants to join, with clear indications that it’s a sandbox and should not be considered safe.

Thanks for patience as we continue to find out way.

For those here in the gloriousness that is infosec.exchange, consider donating to help run the instance - it's seen a MASSIVE uptick in usage with some huge names moving across with their followers. Anything you can do to help is greatly appreciated!

And yes, before you ask, I have donated. I wouldn't ask people to do something I'm not willing to do πŸ’œ

https://liberapay.com/Infosec.exchange/

Infosec.exchange's profile - Liberapay

This will fund operations and hosting costs for the infosec.exchange Mastodon instance. I greatly appreciate any and all donations.

Liberapay
@kevinbruce
# Don't forget FedEx:
🎁 Shipped
πŸš› On its way!
❓ Something went wrong....
πŸ“† .... Er.....
πŸ˜… It's here!
USPS Tracking
1. We're not sure it exists.
2. It's arrived.
Fuck this day. Actually, fuck 2022. I'd take 2020 & 2021 combined over 2022.

Hello mastodon #infosec friends, I built a new website to better search for #Sentinel #AnalyticsRules.

https://analyticsrules.exchange

It is a searchable and filterable list of all Analytics rules in the public repository built automatically twice a day.

Feedback welcome

Microsoft Sentinel Analytic Rules

Microsoft Sentinel Analytic Rules