<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Passionate aboutsecurity</title>
	<atom:link href="https://blog.ismaelvalenzuela.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.ismaelvalenzuela.com</link>
	<description></description>
	<lastBuildDate>Tue, 26 May 2020 13:42:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Do you want to learn how to &#8216;Blue Team&#8217;​? Start with &#8220;Time Based Security&#8221;​.</title>
		<link>https://blog.ismaelvalenzuela.com/2019/09/12/do-you-want-to-learn-how-to-blue-team%e2%80%8b-start-with-time-based-security%e2%80%8b/</link>
					<comments>https://blog.ismaelvalenzuela.com/2019/09/12/do-you-want-to-learn-how-to-blue-team%e2%80%8b-start-with-time-based-security%e2%80%8b/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Thu, 12 Sep 2019 23:57:03 +0000</pubDate>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Blue Team]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[How To Start In Security]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[Network Security Monitoring]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security Operations]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[#allrounddefenders #secops #defendallthethings #sec530 #blueteam]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=421</guid>

					<description><![CDATA[<p>Also available on LinkedIn &#8220;We&#8217;ve been looking at security the wrong way [&#8230;] Fortress Mentality insists that building tall electronic walls is how to keep [&#8230;]</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2019/09/12/do-you-want-to-learn-how-to-blue-team%e2%80%8b-start-with-time-based-security%e2%80%8b/">Do you want to learn how to ‘Blue Team’​? Start with “Time Based Security”​.</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Also available on <a href="https://www.linkedin.com/pulse/do-you-want-learn-how-blue-team-start-time-based-ismael-valenzuela/" target="_blank" rel="noopener">LinkedIn</a></p>
<blockquote><p>&#8220;We&#8217;ve been looking at security the wrong way [&#8230;] Fortress Mentality insists that building tall electronic walls is how to keep the bad guys out. That method hasn&#8217;t worked for 5000 years of warfare, so why should it work for computer security? It can&#8217;t and it doesn&#8217;t.&#8221;<em> &#8212; Winn Schwartau.</em></p></blockquote>
<p>As much as I love to put my red hat on, as I always explain to my <a href="https://www.sans.org/instructors/ismael-valenzuela">SANS</a> students, pentesting or even red teaming, can become &#8216;boring&#8217; over time (sorry guys), especially when you are brought into environments where all the organization wants is to have a green check for yearly compliance purposes, or simply to have one more report to ignore. And trust me, that happens more often than not.</p>
<p>That is why I am so happy to see how many security professionals, experienced or not, are making the shift, joining the blue team ranks to learn how to defend their crown jewels in a highly increasingly complex world where technology advances so fast, data is ubiquitous, networks become more opaque and endpoint devices are less trusted than ever.</p>
<p>If this is your goal, and you are willing to get into an exciting, high paced but also highly rewarding field, where learning never stops&#8230; welcome aboard! Now, where do you start? There are a plethora of resources out there on how to get started into pentesting, but it seems that it is not so easy to find good resources on how to become an effective cyber defender.</p>
<p>There are many resources I can recommend, but since dropping here a list of 100 links won&#8217;t probably help you much, let me recommend you a very easy and light reading to start with: &#8220;Time Based Security&#8221;. Though it was written in 1999, TBS is still one of the most relevant, effective and terribly simple security models you can apply today. The principles enumerated in this book are <strong>absolutely essential</strong> for any blue teamer, regardless of whether you are a CISO, a SOC analyst, a security architect or an incident responder. TBS provides a reproducible method to understand how much &#8216;security&#8217; a product or technology provides, by answering:</p>
<ul>
<li>How long are systems exposed?</li>
<li>How long before we detect a compromise?</li>
<li>How long before we respond?</li>
</ul>
<p>While it is usually applied to auditing, TBS is a very practical model to assess and design security architectures too. The method proposed is very simple, but it provides you with the knowledge and the tools required to make systems more secure and resilient. Here&#8217;s the main idea:</p>
<blockquote><p>&#8220;If it takes longer to detect and to respond to an intrusion than the amount of protection time afforded by the security measures, that is if P &lt; D + R then effective security is impossible to achieve in this system. It should be becoming a little bit obvious that the choice of a good protection system is not the first thing you need to think about when designing a secure network environment. <strong>It’s the efficacy of the detection and reaction processes that really matters.&#8221;</strong></p></blockquote>
<p>If this wasn&#8217;t good enough, Winn allows you to download and read his book for free on his website, so please go and grab a free copy of “Time Based Security” now!</p>
<p><a href="https://winnschwartau.com/wp-content/uploads/2019/06/TimeBasedSecurity.pdf">https://winnschwartau.com/wp-content/uploads/2019/06/TimeBasedSecurity.pdf</a></p>
<p>Want to learn more on #BlueTeam? If so, please let me know, and I will follow up this post with a series of articles on how to improve your cyber defense skills. In the meantime check out the series of webinars that Justin Henderson and I recorded here:</p>
<p><strong><a href="https://www.sans.org/webcasts/defensible-security-architecture-engineering-1-all-round-defender-secret-sauce-109690">Defensible Security Architecture and Engineering – Part 1: How to become an All-Round Defender &#8211; the Secret Sauce</a></strong></p>
<p><strong><a href="https://www.sans.org/webcasts/defensible-security-architecture-engineering-2-thinking-red-acting-blue-mindset-actions-109710">Defensible Security Architecture and Engineering – Part 2: Thinking Red, Acting Blue – Mindset &amp; Actions</a></strong></p>
<p><strong><a href="https://www.sans.org/webcasts/defensible-security-architecture-engineering-3-protect-lunch-money-keeping-thieves-bay-110737">Defensible Security Architecture and Engineering – Part 3: Protect your Lunch Money – Keeping the Thieves at Bay</a></strong></p><p>The post <a href="https://blog.ismaelvalenzuela.com/2019/09/12/do-you-want-to-learn-how-to-blue-team%e2%80%8b-start-with-time-based-security%e2%80%8b/">Do you want to learn how to ‘Blue Team’​? Start with “Time Based Security”​.</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2019/09/12/do-you-want-to-learn-how-to-blue-team%e2%80%8b-start-with-time-based-security%e2%80%8b/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>En Málaga o en Nueva York: Cómo ‘hackear’ tu carrera en ciberseguridad (Spanish)</title>
		<link>https://blog.ismaelvalenzuela.com/2018/12/05/en-malaga-o-en-nueva-york-como-hackear-tu-carrera-en-ciberseguridad-spanish/</link>
					<comments>https://blog.ismaelvalenzuela.com/2018/12/05/en-malaga-o-en-nueva-york-como-hackear-tu-carrera-en-ciberseguridad-spanish/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Wed, 05 Dec 2018 15:54:39 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[How To Start In Security]]></category>
		<category><![CDATA[Papers & Presentations]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[cybercamp]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[fundamentals]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[how to start]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[motivation]]></category>
		<category><![CDATA[think as an attacker]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=405</guid>

					<description><![CDATA[<p>En esta sesión compartiré recomendaciones y experiencias útiles, tanto para aquellos que quieren desarrollar su carrera en ciberseguridad, como aquellos que quieren impulsarla y desarrollar todo su potencial.</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2018/12/05/en-malaga-o-en-nueva-york-como-hackear-tu-carrera-en-ciberseguridad-spanish/">En Málaga o en Nueva York: Cómo ‘hackear’ tu carrera en ciberseguridad (Spanish)</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Presentado en <a href="https://cybercamp.es/" target="_blank" rel="noopener">CyberCamp 18</a>, Málaga, el 30 de Noviembre de 2018 (ver <a href="https://cybercamp.es/programa/agenda" target="_blank" rel="noopener">agenda</a> y <a href="https://cybercamp.es/programa/ponentes" target="_blank" rel="noopener">ponentes</a>)</p>
<p>Full recording of the presentation in English: <a href="https://www.youtube.com/watch?v=bUaVt3rjSwc&amp;t=6991s" target="_blank" rel="noopener nofollow">https://www.youtube.com/watch?v=bUaVt3rjSwc&amp;t=6991s</a> (my talk starts at minute ’59).</p>
<blockquote><p>Si hace 20 años, cuando trabajaba como desarrollador web para una pequeña ‘.com’ en Málaga, me hubiesen dicho que tendría la oportunidad de diseñar, construir y gestionar el programa de ciberseguridad de la red hospitalaria de la ciudad de Nueva York, el de un Banco en Dubai o el de una empresa de software con sede en Sydney, presentar mis proyectos en BlackHat, diseñar productos de seguridad para <a href="https://securingtomorrow.mcafee.com/author/ismael-valenzuela/" target="_blank" rel="noopener">McAfee</a>, liderar iniciativas de seguridad en Intel y formar a profesionales de Microsoft, Amazon, NASA o FBI, ¿qué crees que habría pensado? Obviamente… ¡que era imposible!</p>
<p>Pero, ¿no es en eso en lo que consiste la filosofía ‘hacker’? Hacer posible, lo imposible. Y todo empieza por ‘hackearte’ a ti mismo, crear tus oportunidades y sacar el máximo provecho de aquellas que se presentan. ¿Quieres saber cómo? En esta sesión compartiré recomendaciones y experiencias útiles, tanto para aquellos que quieren desarrollar su carrera en ciberseguridad, como aquellos que quieren impulsarla y desarrollar todo su potencial.</p></blockquote>
<div class="su-custom-gallery su-custom-gallery-align-left su-custom-gallery-title-hover"><div class="su-custom-gallery-slide" style="width:180px;height:140px"><a href="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5301.jpg" target="_blank" title="IMG_5301"><img decoding="async" src="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5301-180x140.jpg" alt="IMG_5301" width="180" height="140" /><span class="su-custom-gallery-title">IMG_5301</span></a></div><div class="su-custom-gallery-slide" style="width:180px;height:140px"><a href="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5302.jpg" target="_blank" title="IMG_5302"><img decoding="async" src="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5302-180x140.jpg" alt="IMG_5302" width="180" height="140" /><span class="su-custom-gallery-title">IMG_5302</span></a></div><div class="su-custom-gallery-slide" style="width:180px;height:140px"><a href="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5303.jpg" target="_blank" title="IMG_5303"><img decoding="async" src="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5303-180x140.jpg" alt="IMG_5303" width="180" height="140" /><span class="su-custom-gallery-title">IMG_5303</span></a></div><div class="su-clear"></div></div>
<p>Slides:</p>
<iframe loading="lazy" src="https://www.slideshare.net/slideshow/embed_code/125048601" width="640" height="519" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe><br/>
<p>Grabación completa del día Viernes, 30 de Noviembre. Mi presentación comienza en el minuto &#8217;59:</p>
<div class="su-youtube su-u-responsive-media-yes"><iframe loading="lazy" width="600" height="400" src="https://www.youtube.com/embed/f7iqRMgjoYo?" frameborder="0" allowfullscreen allow="autoplay; encrypted-media; picture-in-picture" title=""></iframe></div>
<p>Entrevista en el <a href="https://www.diariosur.es/tecnologia/ismael-valenzuela-estar-20181201222152-nt.html" target="_blank" rel="noopener">Diario Sur</a> con motivo de la conferencia:</p>
<figure id="attachment_409" aria-describedby="caption-attachment-409" style="width: 310px" class="wp-caption aligncenter"><a href="https://www.diariosur.es/tecnologia/ismael-valenzuela-estar-20181201222152-nt.html" target="_blank" rel="noopener"><img loading="lazy" decoding="async" class="wp-image-409" src="http://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5334-184x300.jpg" alt="" width="310" height="504" srcset="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5334-184x300.jpg 184w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5334-768x1251.jpg 768w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5334-629x1024.jpg 629w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/12/IMG_5334.jpg 1125w" sizes="auto, (max-width: 310px) 100vw, 310px" /></a><figcaption id="caption-attachment-409" class="wp-caption-text">https://www.diariosur.es/tecnologia/ismael-valenzuela-estar-20181201222152-nt.html</figcaption></figure><p>The post <a href="https://blog.ismaelvalenzuela.com/2018/12/05/en-malaga-o-en-nueva-york-como-hackear-tu-carrera-en-ciberseguridad-spanish/">En Málaga o en Nueva York: Cómo ‘hackear’ tu carrera en ciberseguridad (Spanish)</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2018/12/05/en-malaga-o-en-nueva-york-como-hackear-tu-carrera-en-ciberseguridad-spanish/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Getting SecOps Foundations Right with Techniques, Tactics, and Procedures Zero (TTP0)</title>
		<link>https://blog.ismaelvalenzuela.com/2018/11/01/getting-secops-foundations-right-with-techniques-tactics-and-procedures-zero-ttp0/</link>
					<comments>https://blog.ismaelvalenzuela.com/2018/11/01/getting-secops-foundations-right-with-techniques-tactics-and-procedures-zero-ttp0/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Thu, 01 Nov 2018 23:08:57 +0000</pubDate>
				<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Papers & Presentations]]></category>
		<category><![CDATA[Security Operations]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[SecOps]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[threat hunting]]></category>
		<category><![CDATA[TTP0]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=397</guid>

					<description><![CDATA[<p>TTP0 is a new community project created by SecOps (Security Operations) practitioners for SecOps practitioners</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2018/11/01/getting-secops-foundations-right-with-techniques-tactics-and-procedures-zero-ttp0/">Getting SecOps Foundations Right with Techniques, Tactics, and Procedures Zero (TTP0)</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><a href="https://github.com/TTP0/info" target="_blank" rel="noopener"><span class="il">TTP0</span></a> is a new community project created by <span class="il">SecOps</span> (Security Operations) practitioners for <span class="il">SecOps</span> practitioners. Just like a blueprint is required to design, build and operate any facility, <span class="il">TTP0</span> provides the starting point for building or assessing a security program from the ground up. It focuses on resetting the basics of a security program to ensure a solid foundation. <span class="il">SecOps</span> requires a vision, strategy, and tactical abilities to guide the team and thought leadership to demonstrate effectiveness. Is this guidance a governance or regulation requirement, risks evaluation or leader preference? In this talk, Rob Gresham and Ismael Valenzuela will discuss how <span class="il">TTP0</span> provides the foundation from mission, vision and strategy to aid you in determining which technique is best for the organization, while focusing on individual tactical capabilities along with the <span class="il">procedures</span> that synchronize operations with the business. Using a modular, Lego-based approach,  we will prove how <span class="il">TTP0</span> can provide the necessary building blocks to design, build and operate from a 2 man SOC team to a 1,000 person SOC entity!</p>
<p>Slides:</p>
<iframe loading="lazy" src="https://www.slideshare.net/slideshow/embed_code/121473713" width="640" height="519" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe><br/><p>The post <a href="https://blog.ismaelvalenzuela.com/2018/11/01/getting-secops-foundations-right-with-techniques-tactics-and-procedures-zero-ttp0/">Getting SecOps Foundations Right with Techniques, Tactics, and Procedures Zero (TTP0)</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2018/11/01/getting-secops-foundations-right-with-techniques-tactics-and-procedures-zero-ttp0/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Intelligence Driven Defense: Successfully Embedding Cyber Threat Intel in Security Operations</title>
		<link>https://blog.ismaelvalenzuela.com/2018/10/11/intelligence-driven-defense-successfully-embedding-cyber-threat-intel-in-security-operations/</link>
					<comments>https://blog.ismaelvalenzuela.com/2018/10/11/intelligence-driven-defense-successfully-embedding-cyber-threat-intel-in-security-operations/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Thu, 11 Oct 2018 20:04:42 +0000</pubDate>
				<category><![CDATA[Papers & Presentations]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security Operations]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=393</guid>

					<description><![CDATA[<p>Being able to tell a compelling story that can answer key questions like: who is attacking us, what is their motivation, were they here before, how do they operate, what is the impact to our business, and will they come back, should be one of the ultimate goals of any effective blue team. However, being successful at embedding cyber threat intel in SecOps require something else: maintaining a solid understanding of the environment we are defending, as well as a systematic way to identify and prioritize applicable threats and assess impact, so we can respond appropriately to these attacks.</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2018/10/11/intelligence-driven-defense-successfully-embedding-cyber-threat-intel-in-security-operations/">Intelligence Driven Defense: Successfully Embedding Cyber Threat Intel in Security Operations</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<blockquote><p><em>&#8220;I thought all I had to do was show the data and people would understand. It doesn&#8217;t work. You have to tell a story&#8221; &#8211; Cliff Stoll.</em></p></blockquote>
<p>Easier said than done, right? Being able to tell a compelling story that can answer key questions like: who is attacking us, what is their motivation, were they here before, how do they operate, what is the impact to our business, and will they come back, should be one of the ultimate goals of any effective blue team. However, being successful at embedding cyber threat intel in SecOps require something else: maintaining a solid understanding of the environment we are defending, as well as a systematic way to identify and prioritize applicable threats and assess impact, so we can respond appropriately to these attacks.</p>
<p>In this talk, Ismael Valenzuela, Certified SANS Instructor and GSE #132, will share lessons learned and practical tips on how blue teams can not only consume but also produce actionable and contextual threat intelligence using tools, processes, models and taxonomies that are available to the community.</p>
<p>Slides:</p>
<iframe loading="lazy" src="https://www.slideshare.net/slideshow/embed_code/119143174" width="640" height="519" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe><br/><p>The post <a href="https://blog.ismaelvalenzuela.com/2018/10/11/intelligence-driven-defense-successfully-embedding-cyber-threat-intel-in-security-operations/">Intelligence Driven Defense: Successfully Embedding Cyber Threat Intel in Security Operations</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2018/10/11/intelligence-driven-defense-successfully-embedding-cyber-threat-intel-in-security-operations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Speaking at BlackHat USA 2018</title>
		<link>https://blog.ismaelvalenzuela.com/2018/06/26/speaking-at-blackhat-usa-2018/</link>
					<comments>https://blog.ismaelvalenzuela.com/2018/06/26/speaking-at-blackhat-usa-2018/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Tue, 26 Jun 2018 20:45:05 +0000</pubDate>
				<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[rastrea2r]]></category>
		<category><![CDATA[Security Operations]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[arsenal]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[SecOps]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<category><![CDATA[tools]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=355</guid>

					<description><![CDATA[<p>What is best that speaking at BlackHat USA? Doing it twice! I&#8217;m excited to announce that I&#8217;ll be speaking at BH USA for the 3rd [&#8230;]</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2018/06/26/speaking-at-blackhat-usa-2018/">Speaking at BlackHat USA 2018</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>What is best that speaking at <a href="https://www.blackhat.com/us-18/presenters/Ismael-Valenzuela.html" target="_blank" rel="noopener">BlackHat USA</a>? <strong>Doing it twice!</strong> I&#8217;m excited to announce that I&#8217;ll be speaking at BH USA for the 3rd time in the last 3 years. This time, in addition to speaking on how to integrate cyber threat intelligence in Security Operations with my colleague and friend <a href="https://twitter.com/ChristiaanBeek" target="_blank" rel="noopener">Christiaan Beek</a>, I&#8217;ll be presenting the latest version of my <a href="https://github.com/rastrea2r/rastrea2r" target="_blank" rel="noopener">rastrea2r</a> open source project at BlackHat Arsenal.</p>
<p>If you&#8217;re at BH USA this year, please stop by and say hi!</p>
<p><a href="http://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM.png"><img loading="lazy" decoding="async" class="alignleft size-medium wp-image-357" src="http://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM-297x300.png" alt="" width="297" height="300" srcset="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM-297x300.png 297w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM-768x777.png 768w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM-1013x1024.png 1013w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/Screen-Shot-2018-06-26-at-4.11.51-PM.png 1146w" sizes="auto, (max-width: 297px) 100vw, 297px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>BlackHat USA 2018</strong> &#8211; <a href="https://www.blackhat.com/us-18/presenters/Ismael-Valenzuela.html" target="_blank" rel="noopener">https://www.blackhat.com/us-18/presenters/Ismael-Valenzuela.html</a></p>
<p><strong>BlackHat USA 2017</strong> &#8211; <a href="https://www.blackhat.com/us-17/sponsored-sessions/Ismael-Valenzuela.html" target="_blank" rel="noopener">https://www.blackhat.com/us-17/sponsored-sessions/Ismael-Valenzuela.html</a></p>
<p><strong>BlackHat USA 2016</strong> &#8211; <a href="https://www.blackhat.com/us-16/presenters/Ismael-Valenzuela.html" target="_blank" rel="noopener">https://www.blackhat.com/us-16/presenters/Ismael-Valenzuela.html</a></p><p>The post <a href="https://blog.ismaelvalenzuela.com/2018/06/26/speaking-at-blackhat-usa-2018/">Speaking at BlackHat USA 2018</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2018/06/26/speaking-at-blackhat-usa-2018/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Disrupting the Disruptors: How to Threat Hunt Like a Pro</title>
		<link>https://blog.ismaelvalenzuela.com/2017/12/19/disrupting-the-disruptors-how-to-threat-hunt-like-a-pro/</link>
					<comments>https://blog.ismaelvalenzuela.com/2017/12/19/disrupting-the-disruptors-how-to-threat-hunt-like-a-pro/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Tue, 19 Dec 2017 19:31:54 +0000</pubDate>
				<category><![CDATA[Network Security Monitoring]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[recorded future]]></category>
		<category><![CDATA[threat hunting]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=334</guid>

					<description><![CDATA[<p>Read my article on how to threat hunt like a pro on Recorded Future&#8217;s blog: https://www.recordedfuture.com/cyber-threat-hunting/ Here&#8217;s an excerpt of this article: As the saying [&#8230;]</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2017/12/19/disrupting-the-disruptors-how-to-threat-hunt-like-a-pro/">Disrupting the Disruptors: How to Threat Hunt Like a Pro</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Read my article on how to threat hunt like a pro on Recorded Future&#8217;s blog:</p>
<p><a href="https://www.recordedfuture.com/cyber-threat-hunting/" target="_blank" rel="noopener">https://www.recordedfuture.com/cyber-threat-hunting/</a></p>
<p>Here&#8217;s an excerpt of this article:</p>
<blockquote><p>As the saying goes, the best defense is a good offense. When it comes to cybersecurity, that means shifting from merely responding to intrusions and attacks to actively searching out threats and destroying them. Having the capacity and know-how to make this stance shift is a key element of a mature information security operations center (SOC), says Ismael Valenzuela, who recently gave a presentation on threat hunting at RFUN 2017.</p>
<p>Valenzuela has worked in cybersecurity for decades and has been a member of the Foundstone team at McAfee for six years, performing incident response in the United States, Europe, and the Middle East. He is also a SANS-certified instructor who has taught classes on continuous monitoring, forensics, and security operations for the past seven years.</p>
<p>During his presentation, Valenzuela talked extensively about the difference between incident response and <a href="https://www.recordedfuture.com/podcast-episode-13/">threat hunting</a>, focusing on the qualities that a SOC needs to effectively hunt threats and some of the challenges they face, as well as what he called the three big “knows” that every SOC should focus on: knowing your enemy, knowing your network, and knowing your tools. He concluded his talk with a look at how automation, artificial intelligence, and machine learning are impacting the field, arguing that they are ultimately just new tools that can supplement, but never replace, a team of experienced humans.</p></blockquote><p>The post <a href="https://blog.ismaelvalenzuela.com/2017/12/19/disrupting-the-disruptors-how-to-threat-hunt-like-a-pro/">Disrupting the Disruptors: How to Threat Hunt Like a Pro</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2017/12/19/disrupting-the-disruptors-how-to-threat-hunt-like-a-pro/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Interview: Enterprise Security Weekly #70</title>
		<link>https://blog.ismaelvalenzuela.com/2017/11/23/interview-enterprise-security-weekly-70/</link>
					<comments>https://blog.ismaelvalenzuela.com/2017/11/23/interview-enterprise-security-weekly-70/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Thu, 23 Nov 2017 19:10:05 +0000</pubDate>
				<category><![CDATA[Interview]]></category>
		<category><![CDATA[cyberinsurance]]></category>
		<category><![CDATA[enterprise]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[threat hunting]]></category>
		<category><![CDATA[Training]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=329</guid>

					<description><![CDATA[<p>Thanks to Paul Asadoorian, Doug White and Matt Alderman for having me on Enterprise Security Weekly, episode 70. Enjoy the show! https://wiki.securityweekly.com/ES_Episode70 &#160;</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2017/11/23/interview-enterprise-security-weekly-70/">Interview: Enterprise Security Weekly #70</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Thanks to Paul Asadoorian, Doug White and Matt Alderman for having me on Enterprise Security Weekly, episode 70. Enjoy the show!</p>
<p><a href="https://wiki.securityweekly.com/ES_Episode70" target="_blank" rel="noopener">https://wiki.securityweekly.com/ES_Episode70</a></p>
<p>&nbsp;</p><p>The post <a href="https://blog.ismaelvalenzuela.com/2017/11/23/interview-enterprise-security-weekly-70/">Interview: Enterprise Security Weekly #70</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2017/11/23/interview-enterprise-security-weekly-70/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>My contribution to the &#8220;CDM From The Frontlines&#8221; ebook</title>
		<link>https://blog.ismaelvalenzuela.com/2017/10/20/my-contribution-to-the-cdm-from-the-frontlines-ebook/</link>
					<comments>https://blog.ismaelvalenzuela.com/2017/10/20/my-contribution-to-the-cdm-from-the-frontlines-ebook/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Fri, 20 Oct 2017 20:17:36 +0000</pubDate>
				<category><![CDATA[Continuous Monitoring]]></category>
		<category><![CDATA[Network Security Monitoring]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[CDM]]></category>
		<category><![CDATA[ebook]]></category>
		<category><![CDATA[threat hunting]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=347</guid>

					<description><![CDATA[<p>Thanks to @TenableSecurity for asking me to contribute to their new ebook on Continuous Diagnostics &#38; Mitigation: https://www.tenable.com/whitepapers/cdm-from-the-frontlines</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2017/10/20/my-contribution-to-the-cdm-from-the-frontlines-ebook/">My contribution to the “CDM From The Frontlines” ebook</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Thanks to <a class="twitter-atreply pretty-link js-nav" dir="ltr" href="https://twitter.com/TenableSecurity" target="_blank" rel="noopener" data-mentioned-user-id="34732682"><s>@</s><b>TenableSecurity</b></a> for asking me to contribute to their new ebook on Continuous Diagnostics &amp; Mitigation:</p>
<p><a href="https://www.tenable.com/whitepapers/cdm-from-the-frontlines" target="_blank" rel="noopener">https://www.tenable.com/whitepapers/cdm-from-the-frontlines</a></p>
<p><a href="http://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication.jpg"><img loading="lazy" decoding="async" class="alignleft wp-image-348 size-medium" src="http://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication-300x195.jpg" alt="" width="300" height="195" srcset="https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication-300x195.jpg 300w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication-768x498.jpg 768w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication-1024x664.jpg 1024w, https://blog.ismaelvalenzuela.com/wp-content/uploads/2018/06/CDM_Publication.jpg 1200w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p><p>The post <a href="https://blog.ismaelvalenzuela.com/2017/10/20/my-contribution-to-the-cdm-from-the-frontlines-ebook/">My contribution to the “CDM From The Frontlines” ebook</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2017/10/20/my-contribution-to-the-cdm-from-the-frontlines-ebook/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Machine Learning: Practical Applications for Cyber Security</title>
		<link>https://blog.ismaelvalenzuela.com/2017/08/03/machine-learning-practical-applications-for-cyber-security/</link>
					<comments>https://blog.ismaelvalenzuela.com/2017/08/03/machine-learning-practical-applications-for-cyber-security/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Thu, 03 Aug 2017 13:34:17 +0000</pubDate>
				<category><![CDATA[Machine Learning]]></category>
		<category><![CDATA[analytics]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[orchestration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=383</guid>

					<description><![CDATA[<p>Each day, exponentially more data and computing power becomes available. We're able to task machines to learn and understand more than ever before and, when combined with human analysis, this process can dramatically reduce laborious tasks. However, even with this surge in applicability, machine learning is still often considered a technology of the future.</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2017/08/03/machine-learning-practical-applications-for-cyber-security/">Machine Learning: Practical Applications for Cyber Security</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Presented and recorded as a SANS Webcast on Thursday, August 3rd, 2017, with Chris Pace from <a href="https://www.recordedfuture.com/machine-learning-cybersecurity-applications/" target="_blank" rel="noopener">Recorded Future</a>.</p>
<p>The webinar is available here (registration required): <a href="https://www.sans.org/webcasts/105480" target="_blank" rel="noopener">https://www.sans.org/webcasts/105480 </a></p>
<blockquote><p>Abstract: Each day, exponentially more data and computing power becomes available. We&#8217;re able to task machines to learn and understand more than ever before and, when combined with human analysis, this process can dramatically reduce laborious tasks. However, even with this surge in applicability, machine learning is still often considered a technology of the future.</p>
<p>Join this webcast to:</p></blockquote>
<blockquote>
<ul>
<li>Understand why machine learning is gaining prominence and how it will impact the future.</li>
<li>Learn how you can take machine beyond simple automation and orchestration.</li>
<li>Gain insight into how machines can analyze data to produce threat intelligence.</li>
<li>Examine real-world use cases of how machine learning can drive practical applications in your organization.</li>
</ul>
</blockquote><p>The post <a href="https://blog.ismaelvalenzuela.com/2017/08/03/machine-learning-practical-applications-for-cyber-security/">Machine Learning: Practical Applications for Cyber Security</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2017/08/03/machine-learning-practical-applications-for-cyber-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>On Cyber Security Interviews with Douglas Brush</title>
		<link>https://blog.ismaelvalenzuela.com/2017/01/16/on-cyber-security-interviews-with-douglas-brush/</link>
					<comments>https://blog.ismaelvalenzuela.com/2017/01/16/on-cyber-security-interviews-with-douglas-brush/#respond</comments>
		
		<dc:creator><![CDATA[Ismael Valenzuela]]></dc:creator>
		<pubDate>Mon, 16 Jan 2017 18:31:50 +0000</pubDate>
				<category><![CDATA[Interview]]></category>
		<category><![CDATA[Threat Hunting]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[threat hunting]]></category>
		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=322</guid>

					<description><![CDATA[<p>https://cybersecurityinterviews.com/009-ismael-valenzuela-lets-see-happens/</p>
<p>The post <a href="https://blog.ismaelvalenzuela.com/2017/01/16/on-cyber-security-interviews-with-douglas-brush/">On Cyber Security Interviews with Douglas Brush</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>https://cybersecurityinterviews.com/009-ismael-valenzuela-lets-see-happens/</p><p>The post <a href="https://blog.ismaelvalenzuela.com/2017/01/16/on-cyber-security-interviews-with-douglas-brush/">On Cyber Security Interviews with Douglas Brush</a> first appeared on <a href="https://blog.ismaelvalenzuela.com">Passionate aboutsecurity</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.ismaelvalenzuela.com/2017/01/16/on-cyber-security-interviews-with-douglas-brush/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
