Austin Baker Profile
Austin Baker

@BakedSec

Followers
2K
Following
4K
Statuses
2K

IR at LinkedIn | focused on the intersection of data science, engineering, and cybersecurity | Scooping up APT and bopping them on the head | opinions my own

Joined October 2018
Don't wanna be here? Send us removal request.
@BakedSec
Austin Baker
3 months
Build a career where you always bring something valuable to the table - that can be depth, breadth, or even just unbridled tenacity and grit. If you do this, you'll find there's a seat for you more places than not.
@reprise_99
Matt Zorich
3 months
People often ask me what they should learn or study in cybersecurity and my advice is always the same; aim for technical excellence with things you love to do and aim for broad technical competency in as many related things as you can - a diverse base of knowledge is career gold
0
0
11
@BakedSec
Austin Baker
3 months
@HackingLZ When the red team realizes GDPR applied to them too
0
0
2
@BakedSec
Austin Baker
3 months
RT @elmo: Elmo loves you. ❤️
0
20K
0
@BakedSec
Austin Baker
3 months
When you have a file lock on the investigation timeline so some goober associate doesn't try to merge in their horrendously formatted system timeline into the main one while you're compiling new IOCs to track (it me, I was the goober)
@usgraphics
U.S. Graphics Company
4 months
LOTO (Lock-Out-Tag-Out) cards exemplify peak analog goodness: combining a physical tag, industrial graphics, and a locking mechanism—a critical safety tool to prevent unintentional and unauthorized actions during maintenance. 🧵
Tweet media one
0
0
3
@BakedSec
Austin Baker
4 months
As Brian notes, blameless does not mean without accountability. You have to be able to say "X failed because Y team made Z choice". Blameless means you don't call out individual persons and try to ruin their lives over what is typically an honest mistake.
@arekfurt
Brian in Pittsburgh
4 months
"Blameless" is a very interesting word when it comes to investigations/post-mortems.😏 There are (at least) two very different senses of it: 1. No formal punishment is imposed or fault declared, but who did what where and why are still analyzed. 2. The problem fell from the sky.
1
4
10
@BakedSec
Austin Baker
4 months
@dinodaizovi Granted but I think the lament of most in-the-trenches practitioners is that A. Hardening is unevenly distributed and undo effort is often placed on securing niche attack vectors (the above) and B. Traceability is then neglected or upcharged by vendors for common vectors.
0
0
0
@BakedSec
Austin Baker
4 months
People often misunderstand opportunistic targeting (baiting) employed by threat actors. You know those signs you see stapled to a pole saying you can make XXk a month only if you call this number? Yeah, they don't need to fool you - just the person desperate enough to call them.
0
0
1
@BakedSec
Austin Baker
4 months
@HackingLZ Brb making my agent to translate my slides into crudely drawn mspaint pngs
0
0
2
@BakedSec
Austin Baker
4 months
@FuzzySec @domchell Man if only those bad guys hadn't lost all their scruples! :D
0
0
1
@BakedSec
Austin Baker
4 months
@FuzzySec @domchell Why use good pretext when bad one do?
2
0
2
@BakedSec
Austin Baker
4 months
The conflict between these metrics, the push and pull as the organization grows and churns, is what helps confirm for you that the ecosystem is stable - not stagnant, never stagnant. But consistently operates within the boundaries of what is "acceptable/good" for each.
0
0
0
@BakedSec
Austin Baker
4 months
First World TTRPG Problems: A cool new dark, gritty setting comes out but all your "edgy" friends are now buttoned up IT professionals and only play 5E
0
0
0
@BakedSec
Austin Baker
4 months
@Hexacorn A church because when all else fails in security, pray pray pray :D
0
0
1
@BakedSec
Austin Baker
4 months
@HackingLZ Same thing happening with blue side certificates. Teaching investigation techniques that are largely irrelevant to modern security operations work - which has largely moved towards working entirely in EDR/SIEM land. The cert factory needs fresh bodies for our "unfilled" 1M jobs
0
0
9
@BakedSec
Austin Baker
4 months
@h4wkst3r @XForce @MSFTBlueHat @hthackers Very cool, you will have a wonderful audience :)
1
0
1
@BakedSec
Austin Baker
4 months
@Hexacorn @anton_chuvakin Ah I see - thank you for clarifying :) I haven't run into one of these yet but it sounds fun :D
0
0
1
@BakedSec
Austin Baker
4 months
@_devonkerr_ Cybersecurity got us like:
0
0
1