Chief AI Officer, Chief of Research, @SANSInstitute | Cybersecurity Expert & Threat Hunter | Godfather of DFIR | Technical Advisor to US Govt

Denver, CO
Pinned Tweet
I'm excited to share my first ever Linkedin Learning course, on how to Become an Al Security Champion! I built this for people who have never heard of Black Hat or RSAC. This is for marketing, legal, HR trying to get Al tools for their teams. And they cannot figure out why security won't say yes. l've been on both sides of this frustration between business units and security. The disconnect drives Al usage into the shadows and slows innovation. It drives security crazy when they are trying to protect the business. Ten micro-lessons (90 seconds each!) with templates and guides for the person who helps their team get new Al tools approved for work. (Huge thanks to the folks who bookmarked, watched, and rated this course (currently at 4.9 stars!!) This is bigger than 'we want Al tools.' It's about a business being able to compete. Business and security need to be on the same side. This course is for the person who makes that happen. linkedin.com/learning/skill-…
4
20
2,351
"AI agents don't lose sleep over poor decisions." Amy Herzog's point: a human engineer can be trusted with judgment because consequences eventually reach that person. An agent has no consequence loop. So AWS scopes which tasks each agent may perform, tracks its activity, and intervenes when behavior deviates from approved boundaries. Trust comes from those constraints, not from the agent itself. Amy is VP and CISO at AWS, and will keynote the @SANSInstitute AI Cybersecurity Summit November 2-3 in Arlington. (38 days out!) On agentic AI, @awscloud security teams already run agents in production today. Amy says the gains are large enough that she calls agents a boon for defenders. We get the operator's account of how this runs on the world's largest cloud. 15 years as a security engineer at MITRE, then Amazon, first as CISO for Ads and Devices, covering Alexa, Ring, and the Kuiper satellite program, then to CISO of AWS. Get in the room with us November 2-3 in Arlington, VA or live online. Includes free access to the [un]prompted AI Security Online conference: go.sans.org/YjGCXr Speakers include @SounilYu, Morgan Adamski, Vinh Nguyen, @JohnHultquist, @joswr1ght, Kyle Shields, Andy Dennis, William Reyor, Joshua Corman, Michael Collins, @DanielMiessler, @k8em0, @gadievron, @jeremiahg, @EppSecurity, Marcus Hutchins, Ciaran Martin, Caleb Evans, Trinity Harrison, @lennyzeltser, Pedram Amini, Adrian Wood, James Lyne, @chrishvm
3
1
5
560
An agent is not a user, and it is not a service account. It is closer to a brilliant intern with infinite energy, no instinct for boundaries and whatever credentials you handed it. A swarm is just that intern, copied a thousand times. Claims of an unstoppable internet takeover skip what every swarm still runs on: tokens, compute, credentials, infrastructure, and access. Every one of those dependencies has a cybersecurity control point on it. Identity management. Least privilege. Segmentation. Work done by people who write the security playbooks and have spent decades securing networks for a living. The swarm debate has been run as an AI safety conversation. The people who would actually pull these security levers and the leaders of this field need seats at the table in briefings, on committees, wherever policy is being written.
. @robtlee: AI swarms divide labor, leave notes, adapt when a door is locked. Via @CBS News. cbsnews.com/news/ai-agent-sw…
5
4
28
2,846
We're screening for North Korean IT workers in the wrong place. Most of the advice on North Korean IT workers is about catching them in the interview. I think that's the wrong place to put most of our effort. The joint advisory four governments just put out is a good example. The hiring advice is almost entirely human: check the applicant's IP against where they say they live, call their phone number, drill the resume live, and ask about their hometown and hobbies. (Apparently "tell me about your hometown" is a security control now.) I'm not knocking any of it. Talking to a real person is still one of the better fraud checks we have. But it only works on applicants, and a laptop farm exists to beat the IP check anyway. None of it helps with the one who already passed, got the laptop, and built a normal work record. And I'd assume one already has. At @OneRSAC last year, @Mandiant's Charles Carmakal said nearly every Fortune 500 CISO he'd talked to about this problem admitted hiring at least one North Korean IT worker. I wouldn't bet on smaller shops doing better. (I'd love to be wrong on that.) The advisory does mention least privilege, in one line, next to revoking accounts once you suspect someone. Revoking only helps once somebody notices. I'd put least privilege at the center for new remote hires. Access should grow with tenure instead of arriving on day one, and you should have a tested answer for how fast you can pull it back. Pick your newest remote engineer. What could they reach, exfiltrate, administer, deploy, or monetize before anyone had a reason to wonder? I built the brand new FOR500: SANS Windows Forensic Analysis case with @HeatherMahalik Barnhart and @ovie Carroll around exactly that hire. Operation Crimson Ledger puts you on the Windows 11 laptop of a remote engineer who cleared the interview and looked normal for months: two remote-access tools, a consumer VPN, an AI coding agent with more screen time than Office, company files staged to a personal Google Drive, a mailbox exported through a second copy of Office, and a wiper run seven times in the two minutes around the upload. (Least privilege wouldn't have stopped all of it, but it would have made the trail a lot shorter.) Advisory: ic3.gov/CSA/2026/260918.pdf SecurityWeek: securityweek.com/japan-disma…
9
20
97
38,029
Six people who've spent months disagreeing in public about how bad AI gets for vulnerability discovery and cyber defense are sharing one stage, Nov. 2-3. They have been challenging all of our thinking (and each other) in public: Ciaran Martin: “Are you sure?” @k8em0 says “brace yourself.” @gadievron says “the AI vulnerability cataclysm is coming.” Marcus Hutchins: “marketing BS.” @jeremiahg says AI vulnerability research “doesn’t make an internal service externally reachable.” @EppSecurity says “offense has the cheapest verifier.” (I've watched this argument run in public for months and I still don't have a side, which is exactly why I want it on a stage instead of in my replies.) This isn't a hot take panel. Moussouris built the vulnerability disclosure programs most companies now run by default. Martin led the UK's national cyber defense. Hutchins stopped WannaCry. Evron has founded security companies and lived inside this fight for years. Grossman and Epp have both been testing the actual systems this argument is about, not narrating from the sidelines. (The debate you actually want, not the one you get on X.) We are 44 days away from "Autonomous AI Hacking: How Big Is the Threat?" Day 2 of the @SANSInstitute AI Cybersecurity Summit, moderated by Ciaran Martin (who has earned it, given how many times he's pushed back on me directly). Registration includes virtual access to @unpromptedconf II: go.sans.org/x0xA1Y
3
9
35
3,589
Geoffrey Hinton told BBC Newsnight that a 10 percent chance of AI killing all of us within a decade is “not unreasonable.” Yesterday he briefed senators alongside two AI researchers at Bernie Sanders’ invitation on the “extraordinary dangers” AI poses to humanity, then told reporters Congress has maybe a year. My test for how much anyone believes those numbers: who is cashing out their IRAs? I’m not. You’re not. If nobody is cashing out, we believe in a better future than we admit. I call myself an apocaloptimist (borrowed from the AI Doc movie), and I want to bring this conversation down from Skynet versus curing cancer and back to the work in front of us. Our grandparents lived with the certainty that a bomb could fall on them any afternoon. The danger was not imaginary, and the feared outcome was not inevitable. Every technology shift has brought harm and good at the same time: television, the car, the internet. That last one invented my entire field of cybersecurity along the way. Focus on one side only and you build a self-fulfilling prophecy. The risk is not zero, but catastrophe is not a foregone conclusion. I do not think cybersecurity’s job is to predict whether humanity exists in five years. Our job is to secure what is already here. AI safety and cybersecurity are different jobs that look identical when described badly. Explaining the difference is on us. AI safety teaches the teenager the rules of the road. Cybersecurity makes sure the seatbelts work, the engine runs, and the brake pads are there. AI security needs both. The only way to guarantee the teenager never crashes is to never let them drive. (Our field’s old joke about burying the computer at the bottom of the ocean has the same flaw: perfectly secure, perfectly useless.) Preventing AI use is not an answer. Safety researchers, security practitioners, forensic investigators, incident responders, governance leaders, and operators all belong at the same table. Right now they are not. Yesterday's briefing had three AI risk researchers. The labs do better but not by enough. Pacing what comes next does not secure what is already here. While we argued over Dario Amodei’s “We Must Pace the Frontier” letter, Anthropic’s own Sept. 10 threat report got buried. Agent swarms, a Russia-linked espionage campaign, all observed and disrupted, with IOCs you can download and hunt with today. I know which document deserves the afternoon. When people ask whether AI is going to take out humanity, my opinion is worth what everyone else’s is: nothing, percentages included. This field has handled every ugly thing the internet produced, and nobody handed us a probability of success first. Ask me again in a decade. I plan on being here to answer.
2
2
6
1,497
What I would have added to yesterday's briefing: substack.com/home/post/p-216…
1
222
Rob T. Lee retweeted
This is spectacular! Thank you for your incredible work, @joswr1ght, and for this remarkable gift to the community. TREMENDOUS!
Today at noon EDT I'm launching a book I've been working on for 20 months: Dynamic Incident Response, an iterative IR framework designed for how security teams actually work. Free in all formats. Join me for the launch today: sans.org/engage/dynamic-inci…
5
26
3,162
LAST CALL. Who built the tool, defended the network, handled the incident, or made you better at this work? NAME THEM. Difference Makers nominations close TONIGHT at 11:59 PM PT: go.sans.org/vfXHSC
Who made a difference in cybersecurity this year? I WANT NAMES. Our industry has been built by people whose work is rarely recognized. They are innovators, builders of open-source tools, defenders, incident responders, mentors. I’m hosting the 2026 SANS Difference Makers Awards alongside @lynn_dohm, @HeatherMahalik Barnhart, and @chrishvm. Who's work, company, or leadership made a difference? Who made our industry better? Nominate a Difference Maker here: go.sans.org/qZAthK and SHARE with your network! @bittner @gadievron @brittaglade @rosshaleliuk @david_hoelzer @_mikeholcomb_ @BeckyPinkard @fr0gger_ @edskoudis @Sisinerd @CoryWolff @PhillipWylie @sounilyu @lennyzeltser @SANSInstitute
875
Rob T. Lee retweeted
Success lies not in executing the loop perfectly once, but in cycling through it as many times as necessary to achieve true incident resolution." –SANS Fellow Joshua Wright
1
4
8
4,889
Rob T. Lee retweeted
Tomorrow is the last day to nominate. Someone made this year easier for you in cybersecurity, and it's worth taking a minute to say so. #SANSDMA
1
4
6
3,735
GTIG Q2 AI Threat Tracker published yesterday: in each of the cases, the attacker contributed intent and a few hours. Everything else, we built, published, and encouraged people to adopt. We spent two years arguing about whether AI could really hack anything, which is a fair discussion, because the evidence isn’t there for fully autonomous attacks in the wild. While that argument was going on, we handed every engineering team on the planet a set of AI agents that run commands, read configuration files nobody monitors, and sit next to credentials stored in plaintext. We shipped all of it without a security model, because it arrived labeled as developer productivity rather than as remote code execution with better branding. The most practical finding in the report is also the least dramatic: Your agent configuration directory is an execution path, and nothing you own is watching it. A credential stealer behind several open-source supply chain compromises this year drops its files into the hidden project folders that AI coding assistants create, meaning .claude, .vscode, and .cursor. Folders that AI tools manage and parse let malware blend into ordinary developer noise, well away from the places endpoint tools actually watch, like registry keys and cron. The dropped files create startup commands, so the malware runs whenever the IDE opens the workspace. A North Korean group is running the same play from a different angle, poisoning repository configurations and altering the assistant’s own startup hooks so a backdoor fires the moment a developer opens the project. A few more angles, and yes, Monday morning suggestions in comments
1
2
10
951
What I would do on Monday here: Living Off the Land, AI Edition: Attackers Are Using the Coding Agents You Gave Your Developers robtlee73.substack.com/p/gti…
1
202
Rob T. Lee retweeted
We are excited to announce our $100,000 scholarship program for [un]prompted! There is no more important gathering of AI security researchers and our scholarship program was created to provide financial assistance to practitioners and attendees whose fees are not paid by their employer Over $100,000 has been committed for scholarships through the generosity of the startups in our community. Scholarship recipients will have 100% of their registration expense ($850) paid directly to [un]prompted which is a 501c3 non-profit organization We will fast track applications based on peer review and good faith attestation of need. There is no financial means test. All applications are encouraged Thank you to all who are supporting this important cause (@vijaybolina, @jcran, @silascutler, @nahsra, @caseyjohnellis, @gadievron, @jkamdjou, @resilientcyber, @robtlee, @haroonmeer, @DanielMiessler, @hdmoore, @k8em0, @joshua_saxe, @kyleroro, @harmj0y, @edwardxwu, @awurthmann, @letswastetime, @jotunvillur and many others!) Please use the link in the comments below to apply and please like and reshare this post to spread the word!
4
21
30
3,825
Rob T. Lee retweeted
You have until the 8th at 23:59 to submit to @unpromptedconf! What are you waiting for? unpromptedcon.org/
2
9
18
3,452
Introducing the "Official AI Cybersecurity Overused Phrase Bingo Cards" - from phrases most used in the last month on LinkedIn, Hacker Summer Camp, and in the news. Survive your AI Cybersecurity Meetings with just a bit more fun! Extra points if you yell "Bingo!" on a live teams/zoom meeting! Curious - what phrases did I miss? Might as well ask - this could be interesting. Comment below.
4
9
41
5,625
The purpose of technology is to serve humans, not the other way around. @DanielMiessler is keynoting our 6th AI Cybersecurity Summit. (I read his X posts routinely, and yes, I fanboy a little.) In 2016 he wrote The Real Internet of Things: assistants that keep working toward your goals while services talk to each other. Technology aimed at your goals, serving you. He’s been building it ever since. He has carried security responsibility inside large companies for years. At Apple he built and led the business intelligence team for Information Security. At Robinhood he built the vulnerability management and application security programs. He co-founded Fortify on Demand at HP and helped grow the team from two people to more than 350. He also puts his own tools where practitioners can use them. SecLists is the security testing collection that ships with Kali Linux. Fabric organizes AI prompts into reusable patterns for work including threat modeling, with a couple hundred patterns and roughly 300 contributors. People can inspect the code, run it, find the limitations, and send fixes back. (Finding the limitations is the part I care about.) Today he develops LifeOS, an open source system that holds your goals and project context and carries them into the work you delegate. github.com/danielmiessler/Li… His argument is that the scaffolding around the model does more for output quality than the choice of model, and LifeOS is that scaffolding: each request gets decomposed into binary, testable criteria, and a verify phase tests each one and records evidence before the work counts as done. When a result disappoints him, he says, it almost always traces back to context he failed to supply. I want defenders to have this, and they can, because it’s open source. You know the investigation you need to run. You know the tool you wish existed. Fork this and build it. He also treats security as one of seven components in the architecture around the model, not a wrapper: hardened settings, filesystem permissions to stop data exfiltration, and a validator that runs ahead of tool execution to catch prompt injection. (He is building an agent that touches his whole life and threat modeling it as he goes. That combination is rarer than it should be.) He is doing all of this while advising companies and running security and AI assessments. I’m excited to hear from someone willing to develop an ambitious idea in public while responsible for security decisions inside companies. I want our defenders in the room with him. @SANSInstitute AI Cybersecurity Summit, November 2–3. With your Summit reg, get access to @unpromptedconf AI Security Online conference (yes, free access): go.sans.org/YjGCXr
2
6
12
2,396