Why Nostr? What is Njump?
2024-12-16 10:36:24
in reply to

Kevin Beaumont on Nostr: So in general the incident data is well anonymized. One thing for MS Security ...

So in general the incident data is well anonymized.

One thing for MS Security customers to be aware of - it contains a unique OrgID, timestamps and malware family names, e.g. this one was dealing with Mimikatz, reverse proxy etc mid June this year.

The so what being if you have an incident people might be able to spot it and what you did during incident. It looks like the MS AI team are taking the MS Security data where customers filled out true positive/benign positive/false positive fields.

Author Public Key
npub176rs4lx7gjqwepgg75psfpv7zjj3xz0lyj4n7rux93ftm390sars6fkwlw