Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
neochris
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
neochris
1y ago
Hi HN, has anyone tried: https://github.com/TracecatHQ/tracecat We got workflows, tables and case management. Focused on SecOps, ITOps, and prod eng / infra use cases. Even if you’re on Jira or SNOW, having even a
2.
▲
by
neochris
2y ago
Help us out? I really would like to hear your advice / thoughts / experience in private. Please find me via email (no getting making this public unfortunately)!
3.
▲
by
neochris
2y ago
I am curious though. Have you ever seen an attack path from a personal device compromise to full Cloud account takeover (or something along those lines like an exfil job or cryptojacking). I haven't? Usually compromised personal device
4.
▲
by
neochris
2y ago
Dude. I do not trust Lambdas. I've seen way too many CTFs and Cloud privesc paths to know how one even slightly misconfigured Lambda can led to full admin access. We have a more local solution to query our security logs.
5.
▲
by
neochris
2y ago
This all makes a lot of sense. I agree that SOC2 can be security theatre (I mean a lot of the language of the standard is suggestive, not a requirement). But a lot of your points about having MDM and EDR set up is covered by that cert. It&#
6.
▲
by
neochris
2y ago
D&R at startup scale = set up billing alerts for different resources. Get a good CSPM. Run Trufflehog every pre-commit.
7.
▲
by
neochris
2y ago
We are building out an OSS startup security program: Prowler as the CPSM, Trufflehog for secrets scanning, for code scanning...I personally think GitHub CodeQL is good enough, but please tell me otherwise. Our security model for our AWS inf
8.
▲
by
neochris
2y ago
Thanks for the comment Ross. Folks seem to have strong opinions about integrating or separating workflows and ticketing ala alert inbox. We like integrations a lot, but of course there needs to be security specific innovations on top of &qu
9.
▲
by
neochris
2y ago
Really appreciate the advice here. I also hate security theatre. We will make it triple clear that our Cloud version is JUST for preview, not production. Repeat (as we mentioned in our README) for anybody reading this thread: Cloud is just
10.
▲
by
neochris
2y ago
We're going to work with these guys: https://www.oneleet.com/ . They are awesome.
11.
▲
by
neochris
2y ago
Appreciate the Tines comparison.
12.
▲
by
neochris
2y ago
Startups win by questioning every assumption from first principles. We look forward to the fight.
13.
▲
by
neochris
2y ago
Cloud version. No SSO tax. We're doing a Show HN as we had strong conviction our message would resonate without the "sticky" Launch HN board. Looks like we were right!
14.
▲
by
neochris
2y ago
Glad to hear we are on the right track. Tracecat is still in alpha, but would be great to have your thoughts / opinions / feedback in our Discord community. We are anon-friendly. There's still a lot more we can innovation on.
15.
▲
by
neochris
2y ago
Save time and money. That's what we are here for. Any thoughts on our analysis regarding case management and log storage? These are two technical decisions we made before writing a single line of code to bring down cost and increase va
16.
▲
by
neochris
2y ago
Will post an updated demo with the output and share it here later today! But here is what one response looks like: "Thank you for your report. the AI labelled this email as malicious. It contained the url https://to58gnrroh2
17.
▲
by
neochris
2y ago
Great question! Unlike a pure infrastructure tool (MongoDB, Elastic, Terraform), UI/UX is a critical factor for adopting a SOAR. Even if other companies fork / host Tracecat, we believe we can out iterate the incumbents in buildin
18.
▲
by
neochris
2y ago
As for the MSP program, absolutely 100% yes. Would love to hear your use-case / pain points regarding existing SOARs (both oss and close sourced). Shuffle is the OG of FOSS SOARs, but the momentum behind that project seems to have stal
19.
▲
by
neochris
2y ago
We plan to add integrations and pre-built workflows in the coming weeks. Would love your input in our Discord channel! https://discord.gg/n3GF4qxFU8 We're building a motley crew of blue teamers, security engineers, and
20.
▲
Show HN: Tracecat – Open-source security alert automation / SOAR alternative
(github.com)
264 points
by
neochris
2y ago
|
65 comments
21.
▲
by
neochris
3y ago
Full disclosure: the results are still worse than what you would get from a manually built lab in a live AWS environment. Tried a bunch of SOTA prompt engineering techniques. I found that explicitly defining AWS permissions and identities i
22.
▲
Show HN: Generate malicious CloudTrail logs with AI agents
(simulation.tracecat.com)
2 points
by
neochris
3y ago
|
1 comments