Advertisement · 728 × 90

Posts by Blove

Preview
Exclusive: ICE reactivated its $2 million contract with Israeli spyware firm Paragon, following its acquisition by U.S. capital The cyber division of ICE's Homeland Security Investigations on Saturday quietly lifted a stop-work order put into place by the Biden administration in October.

NEW: Mercenary spyware is coming to the US.

ICE just quietly unsuspended their contract with spyware maker #Paragon.

Remember them? Caught earlier this year being used to hack Italian journalists.

This is bad, let's talk about how we got here 1/

jackpoulson.substack.com/p/exclusive-...

7 months ago 907 637 27 40

Let’s assume that the traditional “confusion matrix” we often use in science for measuring efficacy (TP/FP/FN/TN) is not available (and really, you shouldn’t use it). What metrics would you collect to directly or indirectly measure the efficacy and quality of your detection engineering efforts?

1 year ago 1 0 0 0

Expecting a tidal wave of attacks against knowledge generation.

Old playbook:

Step 1: source some overly academic prose / niche research.

Step 2: Strip any context.

Step 3: Ridicule the scholar & encourage attacks. Denounce the field.

Step 4: Call for federal funding cuts & bans.

1 year ago 91 29 5 4
Post image

#PIVOTcon25 #CfP is open and you can submit your proposals till 7 FEB 2025
Remember
- one track,30m
- no recording/streaming/tweeting. U should feel comfy to share more
- No TLP:WHITE
- Original content only
Let us guide u through with a little meme-thread
#CTI #ThreatIntel 1/10

1 year ago 31 18 1 4

Memes are now, law is later.

1 year ago 1 0 0 0

I’m coming for you for all my graphics needs from now on. Thanks.

1 year ago 2 0 0 0
Preview
a cartoon dog wearing glasses and a hat standing next to another dog ALT: a cartoon dog wearing glasses and a hat standing next to another dog
1 year ago 5 0 1 0
Advertisement

Scenario: You’re airdropped into an org with tons of detection rules. What questions do you ask and why?
So far I’ve been examining source prominence, distribution of tactics (“Coverage”), and I’m working on mapping “intent” (what is the expectation of putting this signal in front of an analyst).

1 year ago 2 1 4 0

Those gloves came off after the demise and diaspora of Conti —which generally coincides with the war in Ukraine. We had 2ish years where healthcare targets were generally the realm of less “prolific” or capable affiliates but that era is long gone, sadly.

1 year ago 1 0 0 0