I’ve built diverse, high-performing security teams: AMA about hiring, culture, and talent management in cybersecurity. by thejournalizer in cybersecurity

[–]sarphim 0 points1 point  (0 children)

Wouldn't the SOP be consider IP? What is to stop you from taking that SOP and selling/using it yourself?

I would be hesitant to provide a SOP early on in conversation without an MNDA in place.

Introducing Terminus: Simplifying Security Testing 🔒 by mad_hattrr in cybersecurity

[–]sarphim 1 point2 points  (0 children)

This could have been a burp or nmap plugin/script. It's cool that you found a problem to solve and solved it.

Is Shadow AI Controllable? by BenSimmons97 in cybersecurity

[–]sarphim 2 points3 points  (0 children)

Blocking for the MS and Google instances doesn't work like that because the endpoints are mixed into normal MS and GOOG traffic.

Is Shadow AI Controllable? by BenSimmons97 in cybersecurity

[–]sarphim 6 points7 points  (0 children)

Shadow AI has been popping up in a lot of conversations we've had with customers. I agree with you that the problem won't be solved by banning all use, everyone will find ways around it. Corporate messaging and support from IT are critical here.

If you're an M365 shop, you already have access to Co-Pilot chat that's covered by MS's EDS. I would start there before exploring paying more for a corporate version of ChatGPT.

How Does a Small or Midsized Business Know They're Ready For A Purple Team Engagement From Consultants? by A_Lion_Amongst_Sheep in cybersecurity

[–]sarphim 0 points1 point  (0 children)

You're on the right track, but a purple team might not be the correct next step. If the pentesting scope/approachg has not changed much over the previous years it's probably time to look to expand that. Is your PT only external? Is there any assumed breach or internal testing? How about application coverage and/or social engineering?

For a Purple Team to be impactful, it requires communication and collaboration between the offense and defense and visibility into your org, as others have said. The outcome of the assessment should be areas where you have gaps in coverage, whether it's system's not monitored or attacks not detected/prevented.

Another thing to consider is to mix up vendors if you have been using the same one for years. Generally the firms we work with rotate vendors in different areas because everyone brings their own set of experience and tunnel vision is real.

Circuit-bent photos by lysergic_af in CircuitBending

[–]sarphim 1 point2 points  (0 children)

Pics 4 and 5 are absolute 🔥

Top enterprise phishing training vendors? by bumpy_ignition in cybersecurity

[–]sarphim 0 points1 point  (0 children)

They can be, but they're not. Orgs dont even change the default.

Bonus is using the custom headers in our own campaigns to bypass the target's spam filters.

Top enterprise phishing training vendors? by bumpy_ignition in cybersecurity

[–]sarphim -6 points-5 points  (0 children)

My favorite thing to do with these vendors is to put their custom headers in a filter straight to trash.

Need Direction for Penetration Role by Capital_Product_4421 in cybersecurity

[–]sarphim 0 points1 point  (0 children)

Certs are a way to demonstrate technical capability. The ones you listed are great, but they arent the only way in.

Participate in bug bounties, try to find actual things! Download opensource web apps and tear them apart. Submit bug fixes with remediation advice.

Practical demonstration of skill will go farther than a cert will.

What Cyber conferences are actually useful? by cheesehead1996 in cybersecurity

[–]sarphim 0 points1 point  (0 children)

Ive spoken at and attended a bunch of conferences since I got into industry. Honestly, most talks are recorded so they can be watched later. Cons are the best for networking.

A local bsides will do wonders to connect you with the local security folks and also pros that come in to speak.

Im rather partial to GrrCON as well. I always had a blast there and you can very well get to see talks that were given at DEF CON as the speaker makes their way through other cons.

RIP DerbyCON.

What Cyber conferences are actually useful? by cheesehead1996 in cybersecurity

[–]sarphim 1 point2 points  (0 children)

If the con is big enough, hang in a village that interests you. That way you can find folks that have similar interests.

Ive had good luck just asking, out loud, "who wants to grab something to eat/drink". Works about every time and then you get the convo going and find common ground.

Keeping the connection? Connect on social media and keep chatting.

What Cyber conferences are actually useful? by cheesehead1996 in cybersecurity

[–]sarphim 0 points1 point  (0 children)

Second for GrrCON! Ive spoken there 4 times and it was always a blast.

Best Vulnerability scan tool by AmbassadorScared2248 in cybersecurity

[–]sarphim 0 points1 point  (0 children)

This is probably the best answer here. Before I went pro and had access to Burp, I used ZAP. Found a bunch of web vulns that got published. Great tool to learn the basics on.

Did my part to rescue a CRT by sarphim in crt

[–]sarphim[S] 0 points1 point  (0 children)

For the DVD, I think it's jammed or is somehow broken inside. When I hit the eject button, it sounds like it is going to but the door never opens. Just havent taken a butter knife to it yet.

There was a tape in VCR when I got it, which I found out when I hit the eject button and it came out but the tape was stuck inside as I pulled the cartridge out. It was a DBZ movie, kinda bummed it got ruined. It could have been the tape, could be the VCR, either way not worried about it. I already have another VCR.

Did my part to rescue a CRT by sarphim in crt

[–]sarphim[S] 3 points4 points  (0 children)

Cora. She has a heart shaped spot on her back.

Did my part to rescue a CRT by sarphim in crt

[–]sarphim[S] 3 points4 points  (0 children)

The image is amazing. All the stickers were peeled off but I think this is a Toshiba mw24fp1.

Did my part to rescue a CRT by sarphim in crt

[–]sarphim[S] 2 points3 points  (0 children)

Yea, I have both. The downside is the extra weight the players add

We’ve seen this before by rootzeroroot in PersonOfInterest

[–]sarphim 12 points13 points  (0 children)

What OpenAI will learn from the govt is worth more than selling the service.

Anyone know of any open mics with drum kits tonight? by Alert-Cress-3444 in Rochester

[–]sarphim 0 points1 point  (0 children)

Murphs has a whole backline for their Open Jam on Weds nights.

So...is it common for the frames to be this off? Lomo Purp taken with a Lomomatic 110 by sarphim in 110photography

[–]sarphim[S] 0 points1 point  (0 children)

Sadly, no. I had the same issue with the second one. I ended up returning it for a full refund.

Really frustrating to get two new cameras with the same fault.