Gun Reform: Speaking Truth to Bullshit, Practicing Civility, and Effecting Change - Brené Brown
If alternatives exist outside of these forced choices (and they almost always do), then the statements are factually wrong. It’s turning an emotion-driven approach into weaponized belonging. And it always benefits the person throwing down the gauntlet and brandishing those forced, false choices.

The ability to think past either/or situations is the foundation of critical thinking, but still, it requires courage. Getting curious and asking questions happens outside our ideological bunkers. It feels easier and safer to pick a side. The argument is set up in a way that there’s only one real option. If we stay quiet we’re automatically demonized as “the other.”

The only true option is to refuse to accept the terms of the argument by challenging the framing of the debate. But make no mistake; this is opting for the wilderness. Why? Because the argument is set up to silence dissent and draw lines in the sand that squelch debate, discussion, and questions—the very processes that we know lead to effective problem solving.
In that moment I said the thing that I’ve felt my entire life but was either too afraid to say or didn’t have the words. I mustered up the most empathy I could and said, “I know that this is a hard and heartbreaking issue, but I don’t think you’re hearing me. I’m not going to participate in a debate where this issue is reduced to You either support guns or you don’t. It’s too important. If you want to have a longer conversation about it, I’m happy to do that. And I wouldn’t be surprised if the same issues piss us off and scare us.”
Needle in a Haystack
An amateur hunts 700-pound elk in the middle of a vast wilderness. How hard could it be?
Enterprise Detection & Response: Hunting for Malware Critical Process Impersonation
Probably the most well-known algorithm for this is the Levenshtein distance. The resultant score is simply a count of the minimum number of single character insert, delete or modify operations it takes to convert str1 into str2. For example, the Levenshtein distance between 'svchost.exe' and 'scvhost.exe' (our example above) is 2 (delete the 'v', then add a new 'v' just after the 'c').
Because the algorithm is so simple, the Levenshtein distance would make a pretty decent choice for most uses, though in this case we're going to use a variant known as the Damerau-Levenshtein distance. The only difference here is that the Damerau-Levenshtein distance adds the transpose (switch adjacent characters) operation. Since transposition is one of the common techniques for creating confusingly similar filenames, it makes sense to account for this in our distance algorithm. With the Damerau-Levenshtein algorithm, the distance between 'svchost.exe' and 'scvhost.exe' is 1 (transpose the 'v' and the 'c').
With that background in mind, let's see how we can apply it across our network to detect malware masquerading as critical system processes.
Defender Spotlight: David Bianco, Security Technologist, Sqrrl
I lead the Security Technologist group at a Cambridge, MA area startup called Sqrrl.  Our product, Sqrrl Enterprise, is an incident investigation and threat hunting solution that combines Big Data to consume and store all your logs, a graph database to help see how they all relate to each other, and automated and machine-assisted analytics to help discover and get to the bottom of security incidents much more quickly than you can with traditional investigation tools like SIEM or Splunk.
What Do You Get When You Cross a Pyramid With A Chain? | Enterprise Detection & Response
Once you have your indicator data arranged by Kill Chain phase, you essentially have a dossier on how that threat acts as it tries to accomplish its missions.
Mark current detections and gaps in detection
Create a plan to close the gap
Triage Any Alert With These Five Weird Questions! | Enterprise Detection & Response
The keys here are:

Providing the user with the context around the alert (what scenario is it intended to detect, what do actual examples of the TPs look like, etc)
Identifying what other information (stuff that's not already in the alert) the analyst needs to see, and providing quick easy access to this (e.g., pivot to examining the PCAP for an alert)
