Live data from Hacker News

Red Team's SIEM

github.com

11–20 of 29 posts

Re: Red Team's SIEM

#11
post #8
post #6

Earlier quoted context omitted.

I did the searching you mention, and I found the info you mention. But the link sucks on its own, for it to the #1 on HN, in my opinion. The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. I'd be curious to know about HN's sorting algorithms, this topic seems such a niche thing that I'm amazed this page reached #1...

> The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. It's also fine for a page meant for a specific audience. It's not like they want to attract random developers working outside security. Whenever someone says something akin to "Hey that project's page didn't explain/market their offering well enough for me!", an obvious…

I actually assumed it was from the GitHub blog from the front page link, so assumed it was from former colleagues / friends (I worked at GH, and know many of the fine people there).

Then I realized it was just a random GH repo and some sort of security tools software. And even then, was full of its own jargon -- blue team / red team / white team. So I could only ask wtf is this even doing here. Like how does this particular security software impact my life as a generalist software developer, or even if I was just some random technologist person.

Re: Red Team's SIEM

#12
post #7
post #6

Earlier quoted context omitted.

I did the searching you mention, and I found the info you mention. But the link sucks on its own, for it to the #1 on HN, in my opinion. The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. I'd be curious to know about HN's sorting algorithms, this topic seems such a niche thing that I'm amazed this page reached #1...

People like to play cool. Everybody here is a wannabe top hacker, or wannabe unicorn startup founder, or a wannabe James Bond. Nothing is inherently wrong or unusual with that.

I was legitimately asking why i should care about this piece of software, or why I would consider in my day to day to life at work or play. Nothing wrong with that.

Re: Red Team's SIEM

#13
post #6
post #4

Earlier quoted context omitted.

TLDR: highly sophisticated tools for cyber security analysts. Yeah had the same reaction. It takes some background to get what they are taking about. Red Team: A team that try to exploit an organisation to find weakness before black hackers find them. [1] Blue Team: A team that tries to protect the org from the red team and fix the exploits. [2] SIEM: Security Information and Event Management. Usually used by Blue te…

I did the searching you mention, and I found the info you mention. But the link sucks on its own, for it to the #1 on HN, in my opinion. The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. I'd be curious to know about HN's sorting algorithms, this topic seems such a niche thing that I'm amazed this page reached #1...

> I'd be curious to know about HN's sorting algorithms

From HN FAQ: The basic algorithm divides points by a power of the time since a story was submitted.

Re: Red Team's SIEM

#14
post #9

It's interesting to see the development of Red team tooling over the last couple of years. It's obviously necessary for red teamers to continue to advance to be able to cope with improving Blue team technology. However Red Team tech. is, by it's nature, dual-use. It's equally useful for "real" attackers to have these capabilities as it is for people emulating real attackers. The nature of open source makes these capa…

> So these capabilities will help "real" attackers in the same way they help red teams...

They do. However if you do not enable the Red Teams with this capacity, it does not follow that the real attackers do not have it. It's a bit like guns. If the police don't have guns, the bad guys still do. The answer isn't to distribute military weapons and tanks to everyone but at least have them as an option for SWAT.

Re: Red Team's SIEM

#15
post #9

It's interesting to see the development of Red team tooling over the last couple of years. It's obviously necessary for red teamers to continue to advance to be able to cope with improving Blue team technology. However Red Team tech. is, by it's nature, dual-use. It's equally useful for "real" attackers to have these capabilities as it is for people emulating real attackers. The nature of open source makes these capa…

> So these capabilities will help "real" attackers in the same way they help red teams... They do. However if you do not enable the Red Teams with this capacity, it does not follow that the real attackers do not have it. It's a bit like guns. If the police don't have guns, the bad guys still do. The answer isn't to distribute military weapons and tanks to everyone but at least have them as an option for SWAT.

yeah it's a tricky question, I mean Red Teams can never fully emulate all classes of attacker as they're still constrained by laws, but more realistic red teams provide more realistic tests :)

What seems to be the case is that lower end attackers who don't have the skills to create fully custom setups (or high end attackers who don't want to risk their own tooling getting discovered) will use "pentesting" or red team tools to enable their attacks.

So the line (if there is one) is how much do you release in that direction. Some/Many people draw the line at dropping 0-Day others might draw it lower or higher...

Re: Red Team's SIEM

#16

Earlier quoted context omitted.

> So these capabilities will help "real" attackers in the same way they help red teams... They do. However if you do not enable the Red Teams with this capacity, it does not follow that the real attackers do not have it. It's a bit like guns. If the police don't have guns, the bad guys still do. The answer isn't to distribute military weapons and tanks to everyone but at least have them as an option for SWAT.

yeah it's a tricky question, I mean Red Teams can never fully emulate all classes of attacker as they're still constrained by laws, but more realistic red teams provide more realistic tests :) What seems to be the case is that lower end attackers who don't have the skills to create fully custom setups (or high end attackers who don't want to risk their own tooling getting discovered) will use "pentesting" or red team…

> dropping 0-Day Does that convey reporting 0 day exploits

Re: Red Team's SIEM

#17
post #16

Earlier quoted context omitted.

yeah it's a tricky question, I mean Red Teams can never fully emulate all classes of attacker as they're still constrained by laws, but more realistic red teams provide more realistic tests :) What seems to be the case is that lower end attackers who don't have the skills to create fully custom setups (or high end attackers who don't want to risk their own tooling getting discovered) will use "pentesting" or red team…

> dropping 0-Day Does that convey reporting 0 day exploits

"Dropping 0-day" usually refers to the act of releasing an exploit for a previously unknown security vulnerability, prior to the product owner being able to deliver a patch for it.

Re: Red Team's SIEM

#18
Am I alone in seeing a trend of Corporations really tooling up their security? I realize that in the age of digital transformation, securing your digital infrastructure is critical. And you have to do it, or your business is at a serious risk... but it keeps getting bigger, additionally so much of security is also physical.

I guess my concern is if you combine this with the longer term trend of the dominance of corporations in our lives in that they seem to be increasingly becoming small nation states of their own. it just seems like we're a few steps away from corporations having their own standing armies, digital and physical... and all the potential problems associated with that.

Re: Red Team's SIEM

#19
post #8

Earlier quoted context omitted.

> The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. It's also fine for a page meant for a specific audience. It's not like they want to attract random developers working outside security. Whenever someone says something akin to "Hey that project's page didn't explain/market their offering well enough for me!", an obvious…

I actually assumed it was from the GitHub blog from the front page link, so assumed it was from former colleagues / friends (I worked at GH, and know many of the fine people there). Then I realized it was just a random GH repo and some sort of security tools software. And even then, was full of its own jargon -- blue team / red team / white team. So I could only ask wtf is this even doing here. Like how does this par…

There are a lot of security experts on HN and I personally find it an interesting topic even though I have very little knowledge of that industry. Since the guidelines are "anything that could be of interest to hackers" and security research consists of creative use of low level software and hardware, I don't see how it's a strange topic for HN at all. I'm sure there are many other articles here that don't intersect with a generalist software developer's area of expertise.

Re: Red Team's SIEM

#20
post #6
post #4

Earlier quoted context omitted.

TLDR: highly sophisticated tools for cyber security analysts. Yeah had the same reaction. It takes some background to get what they are taking about. Red Team: A team that try to exploit an organisation to find weakness before black hackers find them. [1] Blue Team: A team that tries to protect the org from the red team and fix the exploits. [2] SIEM: Security Information and Event Management. Usually used by Blue te…

I did the searching you mention, and I found the info you mention. But the link sucks on its own, for it to the #1 on HN, in my opinion. The page is written with the philosophy: if you don't know what all these terms are, you don't belong here. Which is fine for a random Github repo. I'd be curious to know about HN's sorting algorithms, this topic seems such a niche thing that I'm amazed this page reached #1...

I personally believe it's natural to know what these things are when you're browsing a site called "Hacker News".
Post reply on HN