Down the Security Rabbithole Podcast (DtSR)

Rafal (Wh1t3Rabbit) Los

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.On Twitter/X: https://twitter.com/@DtSR_PodcastOn YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqOn LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

  1. 12h ago

    DtSR Episode 717 - Your UI is B******t

    Guests: Michael Farnum, Sam Van Ryder TL;DR: Most cybersecurity dashboards don’t fail because they’re ugly. They fail because they don’t change what we do next. Description In Episode 717, Rafal sits down with Michael Farnum (Cybersec Community) and Sam (Dragos, a long-time OT and industrial cybersecurity practitioner) to talk about the uncomfortable truth behind security UI/UX: much of what shows up in the GUI is pure noise. We dig into the split between “pretty but useless” interfaces and tools that are practical but painful, then map out what a real practitioner-focused dashboard should deliver: contextual metrics, clear workflows, and data that drives action inside a SOC, an MDR, or an enterprise security team. From SIEM and EDR lessons to product management realities, we unpack why companies miss the mark when marketing drives the roadmap or when engineering builds for engineers only. We also get candid about the analyst ecosystem, the difference between grounded practitioner feedback and “ivory tower” trend-chasing, and how that can steer executives toward tools that are hard to operationalize. Then we move into AI and CTEM, continuous threat exposure management, and why the win isn’t a flashier interface. The win is faster telemetry correlation, so we can answer the questions that matter: is this vulnerability reachable in our environment, is it exploitable, and what should we prioritize right now? We also touch on modern “interfaces” like APIs and MCP, where the UX becomes how efficiently you can get results, even when the user is another machine. If you care about security tools that actually work under pressure, hit play, subscribe, share the episode with a teammate, and leave a review with your biggest UI pet peeve. YouTube Video: https://youtube.com/live/ts2rU1-j4EI Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

  2. Jul 28

    DtSR Episode 716 - What if Context Replaced Alerts Entirely

    Guests: Jason Vest & Josh Neil TL;DR: Alert fatigue is still a problem; detection isn't generationally better - but we have all this AI. So what gives? Description Alert fatigue is not just a workload problem; it is a product design problem. We dig into a provocative claim sparked by a LinkedIn post: today’s “AI SOC triage” can be a band-aid if it only cleans up alerts after the fact instead of improving threat detection where it starts, in raw telemetry and early signal extraction. We’re joined by Jason Vest (CTO at Binary Defense) and Josh (a statistician with experience from Los Alamos, the Department of Energy, and leading the Microsoft Defender for Endpoint data science team). Together we unpack why rules and detection engineering still matter: they encode what we know is bad, but rigid rule matches and atomic alerts can also trap teams in an endless false positive vs. false negative trade-off. Josh goes as far as to argue that alerts should “die in a fire,” pushing us to think in terms of attack stories and enterprise-wide context, not isolated hits. From there we explore what actually scales: when anomaly detection works, why “model everything” breaks down, and how trigger-based just-in-time modeling can build lightweight models on demand, score the nearby context, then disappear. We also talk about moving from alerts to “situations,” using agentic AI to gather more context across identity, endpoint, and network, plus what transparency should look like for model validation and community standards. Subscribe, share this with your SOC team, and leave a review. Where do you think detection should evolve next: better rules, better models, or a world without alerts? YouTube Video: https://youtube.com/live/GYjePXCiKM0 Have something to say? Let's hear it. Support the show >>> Please consider clicking the link above to support the show! -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/ X/Twitter: https://twitter.com/dtsr_podcast

4.3
out of 5
95 Ratings

About

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show.On Twitter/X: https://twitter.com/@DtSR_PodcastOn YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqOn LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

You Might Also Like