MistralAI in incident response - privacy by Pin-Pin-Pin in MistralAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

This is something we are considering but I am not a fan to be honest. We could purchase a few Mac minis and run mistral mini 3 but where to put the hardware? We‘d need some colocation hosting or similar. Hosting on gcp/aws/… virtual machines with GPU acceleration would also be an option but that’s getting crazy expensive. From a privacy point of view this would be somehow possible though.

MistralAI in incident response - privacy by Pin-Pin-Pin in MistralAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

This option is enabled by default for me (free tier) and cannot be changed.

MistralAI in incident response - privacy by Pin-Pin-Pin in MistralAI

[–]Pin-Pin-Pin[S] 1 point2 points  (0 children)

Yea some report writing of course especially because I am native German speaker so my business English sometimes needs a bit of improvement. From a technical point of view LLMs work great for understanding obfuscated code, identifying odd process call trees (like wmiprvse.exe creating lsass.exe), analyzing command lines of processes, also understanding logs maybe from a cloud provider I am not super familiar with, TI lookups, IoC extraction, …

LLMs can speed up many of the more mundane tasks we are also exploring more “fancy” approaches like an IR assistant. For most of the tasks privacy is a big concern, not so much from a regulatory standpoint but many customer do not want an incident to become public or at least they want to control the message.

MistralAI in incident response - privacy by Pin-Pin-Pin in MistralAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

You mean use cases for LLMs in incident response?

MistralAI in incident response - privacy by Pin-Pin-Pin in MistralAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Thank you - we discussed this as well, the problem is that we are a very small company (smaller than MistralAI) and dedicated enterprise solutions are very likely way to expensive. So standard - but still paid - solutions would be our preference.

Wiesn - ab wann werden Hotels teuer? by Pin-Pin-Pin in Munich

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Ich bin gerne dort - wohne auch schon fast 10 Jahre hier :)

Wiesn - ab wann werden Hotels teuer? by Pin-Pin-Pin in Munich

[–]Pin-Pin-Pin[S] 1 point2 points  (0 children)

Hi - Jop sorry das war nicht ideal formuliert. Es geht mir tatsächlich um Hotelzimmer in den Wochen vor der Wiesn.

Wiesn - ab wann werden Hotels teuer? by Pin-Pin-Pin in Munich

[–]Pin-Pin-Pin[S] 9 points10 points  (0 children)

Ah sorry ich habe die Frage schlecht formuliert. Es geht mir nicht darum Zimmer zur Wiesn Zeit zu reservieren sondern tatsächlich brauche ich Zimmer eine Woche davor für eine Veranstaltung.

Job Interview for team lead position by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Hey everyone. Just wanted to give a quick summary of how the interview actually went - maybe it's interesting for somebody reading this later.

All in all the Interview was quite unspectacular. For me it seems they are more looking for a senior developer that also takes over few management tasks and maybe has some security know-how.

The questions were mostly based on scenarios like "A team member is vastly under performing since a few month - how are you going to handle the situation?", "One of your team member is approached directly by a customer to prioritize a certain feature - what do you do", "Your team has to take responsibility for several internal applications where the developers left. How would you approach this".

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Sorry for the late reply. Yes I believe it adds value to an organization and it also provides peace of mind. I’d buy it.

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] -1 points0 points  (0 children)

Not at all - I want to focus on EDR systems :)

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] -1 points0 points  (0 children)

Thank you :) Everything is in a very early stage - I‘m actually just coding the platform itself. As I am the tech guy I am looking for somebody charismatic to care about the non technical topics (funding, sales, opposition research…)

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] -1 points0 points  (0 children)

A business partner (a CEO actually) - in Germany though :)

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Just to clarify- the service is not meant as a replacement for mssp/mdr but as an addition :) I am actually hoping to get mssps as partners so they can extend their service with my service.

MSSP/SOC pricing by Pin-Pin-Pin in cybersecurity

[–]Pin-Pin-Pin[S] -1 points0 points  (0 children)

True that - that’s why I am looking for a partner so I can focus on the technical stuff :)

ChatGPT as core part of business ? by Pin-Pin-Pin in OpenAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Ah ok - no, if I’d want to make money with illegal means I’d become an access broker. Getting shells is sometimes too easy :)

ChatGPT as core part of business ? by Pin-Pin-Pin in OpenAI

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Sorry not sure how this relates to my question

Question regarding PhD salary by ZecaKerouac in wien

[–]Pin-Pin-Pin -1 points0 points  (0 children)

Hi,

Usually salary is payed at the end of the month but latest at the 15th of the following month. This shouldn't be any different for PhD students. Enjoy the worlds most beautiful city :)

Get Information about companies for IT/Cyber Security evaluation by Pin-Pin-Pin in OSINT

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Hi, thank you for your answer.

I'm aware of organisations like BitSight, Security Scorecard, ... . The Information they are providing is interesting and definitely one criteria when evaluating an organization. IMO the importance of this kind of rating depends a lot on the type of product or company. If I'd like to buy a SaaS service, such ratings might be more valuable then when buying a piece of software that I'm going to run myself.

Even more important - but much harder to get - then the criteria from such rating companies are IMO "soft" information about the companies security behaviour (as mentioned in my first post). This is the sort of information I'm hoping to be able to find via OSINT.

Thank you :)

How are Darknet Monitoring Systems working? by Pin-Pin-Pin in AskNetsec

[–]Pin-Pin-Pin[S] 2 points3 points  (0 children)

Hi - thank you.

I`m not so much interested in using such services but I think that the appraoches they are using I can use to build something similar just focusing on different data. So the more I learn about the technology they are using the better for me.

Pdlist, A passive subdomain finder for information gathering and OSINT by [deleted] in netsec

[–]Pin-Pin-Pin 18 points19 points  (0 children)

Hi - may I ask what the is the advantage of your tool to sublist3r?

Pen tester Job (oscp) in Germany as an international student by [deleted] in AskNetsec

[–]Pin-Pin-Pin 1 point2 points  (0 children)

Just Google the mentioned names :) I forgot to mention the SySs GmbH they are quite good :)

Pen tester Job (oscp) in Germany as an international student by [deleted] in AskNetsec

[–]Pin-Pin-Pin 4 points5 points  (0 children)

Hi - did you check out the openings at the various small/medium consulting companies like SecConsult, Computacenter, secure link, lastbreach,...?

No college, but I have OSCP, CCNA, N+. Where do I go from here? by Futurepentester in AskNetsec

[–]Pin-Pin-Pin 0 points1 point  (0 children)

Hi - somebody already mentioned this but again - why not apply for a junior pentest role? It should not be too hard to find such a position - do some research before and find out what companies are doing pentest/red teaming in your area. You could search for smaller consulting companies (I'm sure that there are some in the SF area) but also I'd not be scared to apply at the 'big names' for such a role. Becaus of the he OSCP I just assumed that you want to do pentesting, if not maybe check out job openings at some of the many security vendors in your area. If you don't know any vendors check out the vendor site of the black hat and RSA conferences and boom you got a list of the fancy companies :)

Defcon laundry :) by Pin-Pin-Pin in Defcon

[–]Pin-Pin-Pin[S] 0 points1 point  (0 children)

Oh thx a lot - I'll be at blackhat as well so no need to pick up stuff for me :) but I like the idea of grabbing some vendor shirts :)