Linux Purple Team/Detection Engineering loop
From TTP emulation to custom Prevention policies via Linux Internals. With the adoption of AI, our cybersecurity world has accelerated even further. Based on my experience in training rooms and recent observations from conferences, I conclude that patching is not enough. Detection is also not. Well, they never were, but now it’s so crucial to change priorities. As Linux experts, we need to use our experience and knowledge to drive the development of customized and architecturally just-in-point prevention and response mechanisms to survive the wave of AI-assisted exploitation of everything.
Read now