THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to home

Conversations worth hearing

Podcasts, talks, and practitioner perspectives with a short note on the lesson worth keeping.

Podcast · Darknet DiariesField note

The identity layer is the new perimeter

A breach story that shows how trusted relationships can be more valuable to attackers than zero-days.

IdentitySocial engineering
Brief overview

My takeaway: identity controls need operational safeguards, not only technical policy. Helpdesk procedures are part of the security boundary.

Talk · Detection engineeringConference note

Start with behavior, not tool names

A practical argument for detections that survive when attackers change infrastructure or payloads.

DetectionBehavior
Brief overview

My takeaway: anchor coverage in attacker objectives and observable behaviors, then map the telemetry required to see them.

Interview · Incident responseListening note

What the first hour gets wrong

Experienced responders discuss why premature certainty can narrow an investigation too early.

IRInvestigation
Brief overview

My takeaway: preserve competing hypotheses, record assumptions, and separate observed facts from interpretation.

Podcast · Cloud securityField note

The quiet risk of non-human identities

A discussion of credentials, ownership, and lifecycle failures around service accounts.

CloudIdentity
Brief overview

My takeaway: every machine identity needs a clear owner, purpose, expiry path, and observable baseline.