user avatar
Dr. Anton Chuvakin
@anton_chuvakin
Information security - #SIEM, #DFIR, #EDR formerly at Gartner! Now @GoogleCloud Office of the #CISO; host of @CloudSecPodcast infosec.exchange/@anton_chuvakin
San Jose, CA
Joined January 2008
  • Pinned
    user avatar
  • user avatar
    I am happy to announce that today I join @chroniclesec, the most exciting security start-up that I've ever seen, and the one with (in my opinion) the highest chance of actually changing the world of security. Let the journey begin, again...
  • user avatar
    Somebody cynically pointed out to me that some orgs have literally millions to pay ransom but cannot find any money for security. (1/3)
  • user avatar
    Name your favorite security advice that is correct in theory but practically not done or not even doable? "Encrypt everything", "patch fast", "classify all your data", "know your environment well", etc. #fun
  • user avatar
    #SIEM is too hard. #SOAR is too hard. #EDR is too hard. Now, if you combine them all into #XDR, now that ... that would be simple?! Duh. Obviously. Why didn't anybody think about it before? #ironic
  • user avatar
    During a podcast today, the concept of "blueteam 'zero day'" came up, a detection method so dramatically novel that it needs to be kept secret from the attackers. How common do you think this is? #question
  • user avatar
    So, anybody care to share their favorite resources on #SOC metrics? I am doing a post related to this and wanted to drop a list of everybody's fave links on measuring SOC performance (yes, including mine too) #request
  • user avatar
    First-ever @Google Cybersecurity Action Team threat report Threat Horizons is out!!!
  • user avatar
    So, today I joined @GooglelCloud Office of the CISO, a part of the organization led by @philvenables - and I am really really really really excited about it! Fun fact: this is the first time in my security career I actually report up to a #CISO :-)
  • user avatar
    @MITREattack just released Top ATT&CK Techniques, a new resource for prioritizing what to defend against first:
  • user avatar
    I love detection engineering, I think it is awesome and hugely needed, and its the future and all that. But I have no idea how to talk about it to a team of 1 (ONE) running a SIEM ...
  • user avatar
    "New Paper: “Future of the SOC: SOC People — Skills, Not Tiers" buff.ly/3nL4Dxz <- a new #SOC paper that we long promised; focus on the people side of SOC
  • user avatar
    Seriously, if you are asking for "MITRE ATT&CK *compliance*", you are ****REALLY**** not approaching threat detection right. Like seriously WTF? :-) #random
  • user avatar
    Today I am writing a guide on the following topic: how to talk to idiots who believe that fully-automated, humanless, autonomous #SOC is coming any day?