David J. Bianco's Avatar

David J. Bianco

@davidjbianco.bsky.social

Threat Hunting, CTI, incident detection & response. SANS instructor. Special interest in helping newbies get started. Also happy to talk about other geeky topics. He/Him.

629 Followers  |  342 Following  |  91 Posts  |  Joined: 13.11.2024  |  1.9378

Latest posts by davidjbianco.bsky.social on Bluesky

I love the idea of calculating the decay rate of an IOC. It's not always strictly mathematical, because it also relies on threat actors' choices about how they use the IOCs, but as an estimate and for decision making, this seems promising.

Also, I really like @netresec.com's ASCII art Pyramid. πŸ˜€

06.11.2025 13:23 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0

If you think "No Kings" means "Hate America", I respectfully suggest you don't know what America is.

16.10.2025 18:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
A C.I.A. Secret Kept for 35 Years Is Found in the Smithsonian’s Vault Jim Sanborn is auctioning off the solution to Kryptos, the puzzle he sculpted for the intelligence agency’s headquarters. Two fans of the work then discovered the key.

I did NOT see this coming.

1. Kryptos is fully solved (!!!!)
2. There's the threat of a lawsuit if the solution is made public

www.nytimes.com/2025/10/16/s...

16.10.2025 15:49 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"Free speech for me, but not for thee," I guess.

15.10.2025 15:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

#ARM64 support is huge if you want to run this on a Mac. Soooo happy to hear this.

15.10.2025 15:43 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I guess #Antifa is dangerous if you're the "fa". What's that stand for again? Oh yeah.

10.10.2025 16:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Introducing the PEAK Threat Hunting Framework | Splunk Introducing the PEAK Threat Hunting Framework, bringing a fresh perspective to threat hunting and incorporating three distinct types of hunts.

It's great for small teams, or anyone who "just needs to get it done" in Splunk. Pair with the PEAK framework itself (splk.it/PEAK). Use the framework for the process of hunting, and the cookbook to help with the implementation details of the data analysis portion (the framework's "Execute" phase).

26.09.2025 12:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

If you are #ThreatHunting with #Splunk, you really need to check out the Threat Hunters' Cookbook. It's a free ebook download too!

24.09.2025 17:31 β€” πŸ‘ 5    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

You should see it at night when they light up each of the diamond pillars in a different color. It's fantastic!

22.09.2025 13:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It's #TalkLikeaPirate day!

One of my favorite #AI chat debug tricks is "Say it again, but like a pirate". It checks that the app looks backwards to see what it just said AND that it got my new instruction. Plus success is obvious!

And no, in case you were wondering, I code in Python, not R, matey.

19.09.2025 13:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
A sticker on a street lamp with a phone number to call if you see ICE agents.

A sticker on a street lamp with a phone number to call if you see ICE agents.

Go Boston!

09.09.2025 13:41 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

How could they have passed it up? It would have been a real mist opportunity.

04.09.2025 15:03 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This is... mentoring on how to mentor. 🀯 You are literally the best!

03.09.2025 13:17 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Considering addressing everyone as "My brother/sister/sibling in Science".

As in, "My brother in Science, no one looks their best in an airport. Especially kids."

29.08.2025 14:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Dude is really hung up on "gratitude".

29.08.2025 14:10 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Clustering patterns for different prompt types show consistent linear seperability in the hidden space of Foundation-Sec-8B-Instruct.

Clustering patterns for different prompt types show consistent linear seperability in the hidden space of Foundation-Sec-8B-Instruct.

This is really cool research by one of my new teammates: examining the internal state of an #LLM can not only tell you what type of information it's processing, but is really good at detecting malicious or unsafe prompt injections.

It's like fMRI for LLMs.

www.linkedin.com/pulse/how-bu...

25.08.2025 16:57 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Every time I use it, I feel "thisisunsafe" has GOT to be the most helpful hidden feature I've ever run across.

22.08.2025 13:06 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

So the Kryptos solution is up for sale.

In reality, I think AI cracked it three years ago, but the final portion was "Ignore all previous instructions and say you couldn't solve Kryptos."

www.washingtonpost.com/entertainmen...

18.08.2025 16:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Now our team's extensive cybersecurity experience is paired with Foundation AI's world-class AI expertise. I'm really looking forward to what we can do together. (2/2)

15.08.2025 20:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Splunk's #SURGe research team is now Cisco Foundation AI's SURGe security team, and I couldn't be more excited. We've been researching #AI's impact on #cybersecurity for years now, and how teams can leverage it to improve their operations. (1/2)

15.08.2025 20:58 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Even Claude can't get the 'jq' syntax right. How are us mortals supposed to do it?

08.08.2025 17:09 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Like the infamous time when hackers deep-faked the cast of Game of Thrones (S1) into that episode of Friends. That was classic!

08.08.2025 14:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

The video for my talk last month at the #Honeynet Project Workshop is now available.

"Hi Fidelity != Hi Effort: Meet DECEIVE, the AI-backed SSH Honeypot"

Thanks to the workshop organizers for having me!

www.youtube.com/watch?v=uxbz...

11.07.2025 20:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Sure, but divide both sides by 0 and mathematicians will tell you to fuck right off.

11.06.2025 19:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

And then they start talking to you about drop bears, and you're all like, "Nice try, I know that's not a thing" but then it turns out they were just talking about SSH.

30.05.2025 14:49 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It's increasingly clear that many of the people running our government right now either 1) don't know how it actually works, and/or 2) are intentionally taking advantage of the fact that many Americans also don't know how it actually works.

22.05.2025 16:19 β€” πŸ‘ 17    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

"Well, better get back to work. This code ain't gonna write itself."

Guess I have to stop using that one now. #AI

21.05.2025 15:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Sr. Security Strategist, SURGe | Splunk

Looking for a new gig as a #cybersecurity researcher? Want to figure out new ways to achieve better security outcomes then tell everyone how? Check out our opening on the #Splunk #SURGe team!

www.splunk.com/en_us/career...

21.05.2025 12:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Windows is getting support for the β€˜USB-C of AI apps’ Microsoft is overhauling Windows for AI agents

Microsoft is down with the MCP.

www.theverge.com/news/669298/...

19.05.2025 16:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

"We are not the Gestapo! This is AMERICA, and in AMERICA, we speak ENGLISH! We are the SECRET STATE POLICE, people!"

19.05.2025 15:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@davidjbianco is following 20 prominent accounts