4 ms·
I completely agree but think this shows a failing of "blue team" culture and education. I now started work in a massive project with half a dozen companies shar
by 616c 8y ago
I completely agree but think this shows a failing of "blue team" culture and education. I now started work in a massive project with half a dozen companies sharing massive AWS VPCs. They have limited security team oversight and coordination. Wouldn't it be nice of they had sufficient levels of access to Snort Suricata data and could learn what normal operations looks like and educate themselves to look for poorly documented systems that are not hooked up to SIEM or even the APM correctly or are failing to talk to different EC2 instances correctly and help? Inventory and ops is sexy and not security but why countless times I see younger SOC kids know absolutely nothing about what their environment looks like. That data would not help them even if they are allowed out if the kiddie sandbox and only allowed to read baked queries and alerts.
The reason this stuff is useless is bc I have never met someone with sufficient experience to act on it for any context, bc people think the tools magically bring educated talented people.