David J. Bianco

@davidjbianco.bsky.social

Threat Hunting, CTI, incident detection & response. SANS instructor. Special interest in helping newbies get started. Also happy to talk about other geeky topics. He/Him.

For years, I've been very clear: "You can't automate threat hunting. It is an essentially human process." Now I'm not so sure. Read why I've reconsidered my stance in my latest post: "The Hunter's Paradox: Is it time to embrace automated threat hunting?" blog.talosintelligence.com/the-hunters-...

The Hunter's Paradox: Is it time to embrace automated threat hunting?

Humans can no longer keep up with the volume and velocity of security data on their own, but AI can't be fully trusted. David discusses the merits of both and muses on what the future might look like.

blog.talosintelligence.com

My local Nextdoor is apparently very worried about Russian interference in the 2026 US elections. The good news is that there is very little chance of that happening. The bad news is that the reason the Russians won't interfere is because we're doing a good enough job of it all by ourselves.

Some recent(ish) updates to CFPlease.io: - Shareable links to CFPs and events - Submit your own events to the queue (moderation req'd) - A public API for searching and filtering Looking for a place to present your cybersecurity research, or just a cool conference to attend? Give it a try!

EvidenceForge v1.10.0 brings major updates: - Far more realistic, configurable email activity. Also produces .eml files as artifacts. - Configs can be split into modular, reusable components, making it easy to define a consistent org/environment across scenarios. github.com/Cisco-Talos/...

GitHub - Cisco-Talos/EvidenceForge: Generate realistic synthetic security logs for cybersecurity threat hunting training and research

Generate realistic synthetic security logs for cybersecurity threat hunting training and research - Cisco-Talos/EvidenceForge

github.com

If AI driven attacks become more prevalent, it'll only be a matter of time before attackers push the token burden on to their victims, using the AI that's already (probably) there. I'm calling it "living off the lAInd".* *Jokey name. Probably will happen, though.