Activity
Mon
Wed
Fri
Sun
Jun
Jul
Aug
Sep
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
What is this?
Less
More

Memberships

ECA Cyber Range

39 members • $97/month

40 contributions to ECA Cyber Range
Recording of ECA Cyber Range Monday, April 27 AMA Session
Good morning ECA Cyber Range Members!! What better way to wake up while drinking your favorite caffeinated beverage of choice than watching (or rewatching) last night's ECA Experts AMA Session! Members showed up and brought some great questions. Our main topic and focus was AI where @Philip Zangara asked a fantastic question about time spent on learning Splunk Cyber Skills vs. AI and LLM skills. If you have heard us talk about this before then you need to listen to this again as there are updates in the response - yeah, kind of like how AI gives you a different answer to the same question the very next day. I wonder where AI learned that? HA! In addition I cracked open the door on a new cybersecurity topic - DevSecOps. You may have heard of it....maybe even read a little about it....but I thought some time needed to be spent laying a foundation for it as from a cybersecurity learning and potential work perspective, its a whole new world of things you can pick up, focus on, and help organizations. Why? Because if AI is going to crank out code faster than developers, we have to protect that code too! Take some time, enjoy the recording, and I hope you walk away with some great nuggets of learning! The recording will be posted up in the Classroom too along with the other past recordings. Enjoy! šŸ˜Ž
0
0
Recording of ECA Cyber Range Monday, April 27 AMA Session
ECA Experts AMA - Monday, April 27th at 7:00pm CST - Asking For Topics
TGIF ECA Cyber Range Members!!! Friendly reminder to you all - Monday, April 27th at 7:00pm CST we will be hosting an AMA session! We do not have a specific topic for this session so feel free to post up, share, and open up topics here in this thread! Nothing is off limits and I'm happy to help out with any subject matter related to cybersecurity, company's I've worked with, subject matter we have covered, servant leadership, and anything else that you would like to tackle. Looking forward to spending time with you all Monday night! šŸ˜Ž
0 likes • 11d
@Philip Zangara Great questions and topic, Philip! Not specifically this question, but yours is an evolution of the question for sure. I'd be happy to dive into this and share my thoughts and understanding.
LinkedIn Article: Don't Start Your Job Search Until You Do This
Happy Saturday Morning, ECA Cyber Range Members! Some of you have asked about people I follow, read, and even get advice/guidance from. And while I've got a variety when it comes to cyber security, we also need people that we can get ideas, guidance, recommendations, and help from for career advice. I've helped some of you and even provided some guidance from time to time. But, one person I'd highly recommend you follow is Liz Ryan. She does share a lot about building your own business, but, she also helps with landing roles and jobs that you want. This week, her article had some great insights and she actually shared some direction I've even given before. It may sound familiar to you, but giving this article a read just builds and compounds whatever foundation you already have. So take some time and dive into this post - it'll help you and hopefully you walk away with a renewed plan and direction for landing that role you want: https://www.linkedin.com/pulse/dont-start-your-job-search-until-you-do-liz-ryan-w4vae/ Enjoy! šŸ˜Ž
0 likes • 18d
@Todd Graham You're very welcome!
ECA Splunk Security Dashboard Challenge Submittion
Full code and documentation on GitHub: https://github.com/philipzangara/splunk-otx-cti-dashboard LinkedIn: https://www.linkedin.com/posts/philip-zangara_splunk-cybersecurity-threatintelligence-share-7450251695206383616-ffEr/ YouTube walkthrough: https://www.youtube.com/watch?v=auqXgulY5-c A Splunk CTI dashboard that correlates AlienVault OTX threat intelligence against live Sysmon endpoint telemetry; to answer the question is the threat intelligence from the outside world actively hitting my environment right now?
0 likes • 22d
Awesome work on the dashboard, Philip! Looks really good! The one question I have is that if you have a confirmed hit on a malicious file hitting one of your systems, then why is the Severity indicator set to Low and green? To me, if it is confirmed and we have evidence then we have compromise or even potential for persistence which means that system could be used for C2 and lateral movement unless we quarantine and begin remediating. I may be mistaken or not understand that correctly, but thought I'd ask about that. Keep up the awesome work!
1 like • 22d
@Philip Zangara I totally understand the issue. Severity is subjective and is only objective once someone gives you an idea of the threshold for each level. The only thing I'll say is that if a system is showing TTP's of hashes that match compromise, to me, that severity is at high or critical, depending on the type of compromise, as you shared with mimikatz.exe.
ECA Cyber Range Monday Session - Splunk ML/AI AMA
What's going on ECA Cyber Range Members?!?! You've heard us talk about it! You've even seen it on the calendar (and then get rescheduled)! But last night, April 13th, it finally happened! That's right, we had the infamous OG Splunker/Cribl GOAT and resident DJ at large, @Paul Stout join us on the Monday AMA to share the Splunk ML/AI capabilities and high-level showcase what is possible within Splunk when it comes to your ML use cases. For me, it was a little walk down memory lane as I shared about how we got here and why. What used to be the old Machine Learning Toolkit has been transformed into the AI Toolkit with Machine Learning and it's what you need if you want to be successful at taking your Splunk data and mining ML use cases. So when you have a moment, give the recording a listen and fee free to let us know if you have any questions! What's coming? Well, for future Monday Night AMAs we here some rumblings that @Omar Sangurima is itching to get back in front of all of you to do another GRC Dojo (yeah, that's what we are calling it for now) session! When? TBD....so stay tuned! Have a good one y'all! šŸ˜Ž
ECA Cyber Range Monday Session - Splunk ML/AI AMA
0 likes • 23d
You are very welcome, @Ivan Oyola! We are sorry you couldn't join in and add to the audience participation, but I'm glad you were able to get some value out of the recording!
0 likes • 22d
@John Samedy That is fantastic to hear! Very happy to know you got something you can bring back to your team to dig into and use with Splunk AI.
1-10 of 40
Paul Daigle II
3
1point to level up
@paul-daigle-ii-1245
Paul has over 24 years of experience working through complex technical challenges in cybersecurity, OT/ICS, networking, and telecommunications.

Active 19h ago
Joined Oct 14, 2025
ESFJ
Cypress, TX
Powered by