Find partners
Down the Security Rabbithole Podcast (DtSR)

Down the Security Rabbithole Podcast (DtSR)

Hosted by Rafal (Wh1t3Rabbit) Los

Episodes

755

Latest episode

Aug 2026

Language

EN

About the show

This is Cybersecurity's premier podcast. Running strong since 2011 Rafal Los, James Jardine, and Jim Tiller bring a no-nonsense, non-commercial approach to our profession. DtSR brings interviews and discussion with people you want to meet, and stories you have to hear. So whether you're just starting out, or are decades deep into your career, you'll always learn something on this show. On Twitter/X: https://twitter.com/@DtSR_Podcast On YouTube: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq On LinkedIn: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/

Listen to episodes

60 recent
August 11, 202635 min

DtSR Episode 718 - Black Hat Recap And The Rush To Rebrand Everything

Guest: Dr. Chase "ZeroTrust" CunninghamTL;DR: AI Marketing slop took over Black Hat Las Vegas 2026, and Rafal sits down for a one-on-one with Chase Cunningham. Featuring their patented level of snark, real analysis, and hype detection, it's a fun conversation.DescriptionBlack Hat is supposed to be where the security industry shows its best work. This year, it also showed its biggest temptation: slap “AI” on everything, crank the volume, and sort out the truth later.We break down what we saw on the floor and what it says about cybersecurity right now, with Chase Cunningham (Dr. Zero Trust) bringing receipts from vendor go-to-market changes and the money flowing into “AI-first” security startups. We talk about why so many tools sound identical, how “AI infrastructure” became the new catch-all label, and why the word “leader” stops meaning anything when everyone uses it. Then we get practical: how do you ask a booth team to define their artificial intelligence, what counts as autonomy, and what answers should make you walk away?The conversation gets real when “AI security” turns out to be a polished UI sitting on top of a large language model API call. We dig into vendor lock-in, pricing and subsidy risk, and the uncomfortable question of who eats the impact when model providers change costs or terms. From there we go straight at the hottest promise in security operations: autonomous SOC and agent swarms. Non-deterministic models can be useful, but mistakes at machine speed can turn into outages and bad calls, so we map where automation helps and where humans still matter.We also call out what we didn’t see: serious talk about hiring, growing junior talent, or serving SMB security needs even though many breaches flow through third parties and smaller vendors. If you care about security outcomes more than security slogans, this one’s for you. Subscribe, share, and leave a review, then tell us: what’s the most inflated AI claim you’ve heard lately?YouTube video: https://youtu.be/mww1YpP-J0kHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

August 4, 202640 min

DtSR Episode 717 - Your UI is Bullshit

Guests: Michael Farnum, Sam Van RyderTL;DR: Most cybersecurity dashboards don’t fail because they’re ugly. They fail because they don’t change what we do next.DescriptionIn Episode 717, Rafal sits down with Michael Farnum (Cybersec Community) and Sam (Dragos, a long-time OT and industrial cybersecurity practitioner) to talk about the uncomfortable truth behind security UI/UX: much of what shows up in the GUI is pure noise. We dig into the split between “pretty but useless” interfaces and tools that are practical but painful, then map out what a real practitioner-focused dashboard should deliver: contextual metrics, clear workflows, and data that drives action inside a SOC, an MDR, or an enterprise security team.From SIEM and EDR lessons to product management realities, we unpack why companies miss the mark when marketing drives the roadmap or when engineering builds for engineers only. We also get candid about the analyst ecosystem, the difference between grounded practitioner feedback and “ivory tower” trend-chasing, and how that can steer executives toward tools that are hard to operationalize.Then we move into AI and CTEM, continuous threat exposure management, and why the win isn’t a flashier interface. The win is faster telemetry correlation, so we can answer the questions that matter: is this vulnerability reachable in our environment, is it exploitable, and what should we prioritize right now? We also touch on modern “interfaces” like APIs and MCP, where the UX becomes how efficiently you can get results, even when the user is another machine.If you care about security tools that actually work under pressure, hit play, subscribe, share the episode with a teammate, and leave a review with your biggest UI pet peeve.YouTube Video: https://youtube.com/live/ts2rU1-j4EIHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

July 28, 2026Episode 71632 min

DtSR Episode 716 - What if Context Replaced Alerts Entirely

Guests: Jason Vest & Josh NeilTL;DR: Alert fatigue is still a problem; detection isn't generationally better - but we have all this AI. So what gives?DescriptionAlert fatigue is not just a workload problem; it is a product design problem. We dig into a provocative claim sparked by a LinkedIn post: today’s “AI SOC triage” can be a band-aid if it only cleans up alerts after the fact instead of improving threat detection where it starts, in raw telemetry and early signal extraction.We’re joined by Jason Vest (CTO at Binary Defense) and Josh (a statistician with experience from Los Alamos, the Department of Energy, and leading the Microsoft Defender for Endpoint data science team). Together we unpack why rules and detection engineering still matter: they encode what we know is bad, but rigid rule matches and atomic alerts can also trap teams in an endless false positive vs. false negative trade-off. Josh goes as far as to argue that alerts should “die in a fire,” pushing us to think in terms of attack stories and enterprise-wide context, not isolated hits.From there we explore what actually scales: when anomaly detection works, why “model everything” breaks down, and how trigger-based just-in-time modeling can build lightweight models on demand, score the nearby context, then disappear. We also talk about moving from alerts to “situations,” using agentic AI to gather more context across identity, endpoint, and network, plus what transparency should look like for model validation and community standards.Subscribe, share this with your SOC team, and leave a review. Where do you think detection should evolve next: better rules, better models, or a world without alerts?YouTube Video: https://youtube.com/live/GYjePXCiKM0Have something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

July 21, 2026Episode 71539 min

DtSR Episode 715 - Reducing The Toil of the SOC Analyst

TL;DR: David Kennedy & Larry Whiteside, Jr. join the podcast to talk about how 'alerts' are a terrible measure of work in the SOC, and what we're doing about it. We discuss the analyst experience, why it's so difficult and leads to burning our best staff out, and also David introduces his latest: NightBeacon CMD. You need to hear this.I'm starting to edit my own videos, so hopefully you like the new format.YouTube Video: https://youtu.be/aMTFaXwRl_AHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

July 14, 2026Episode 71432 min

DtSR Episode 714 - Limitations and Expectations for AI SOC Part 2

TL;DR: This week's pod is the conclusion to the 2-part series on AI SOC with Anton Chuvakin, Daniel Miessler, Rock Lambros, Erik Bloch, and Raja Mukerji. We talk about the rational application of AI to cybersecurity and what the future holds for the various options. You won't want to miss this one.Youtube Video: https://youtu.be/5YIpZuQLTMgHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

July 7, 2026Episode 71331 min

DtSR Episode 713 - Limitations and Expectations for AI SOC Part 1

TL;DR: Join Raja Mukerji, Anton Chuvakin, Daniel Miessler, Rock Lambros, and Erik Bloch for a banger of an episode (part 1 of 2) where we debate the potential of AI and the current state of delivery for SOC and security applications.This episode was made possible by a group of people with much better things to do than record a podcast who donated their time. Please join me in thanking them for their generous contributions.YouTube video: ...coming soon, blame AntonHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

June 30, 2026Episode 71232 min

DtSR Episode 712 - Lies My AI SOC Salesman Tells

TL;DR: Seth Summersett of Embed Security joins the podcast to talk about the snake oil that's coming from the AI SOC sellers. There's such a significant gap between what you're being sold and what's real. Seth and the gang talk about what's real, what you should expect, and where the line of bullsh** is.YouTube video: https://youtube.com/live/Z8R19cjTjwA?Have something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

June 23, 2026Episode 71134 min

DtSR Episode 711 - Tim Chase Boring but Necessary

TL;DR: This week's pod features Tim Chase, a field CISO and, by background, a practitioner. We talk about "prioritization", a topic that's boring but incredibly necessary, as I am confident nobody out here has this solved yet!YouTube Video: https://youtube.com/live/099rUu0pV0gHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

June 16, 2026Episode 71047 min

DtSR Episode 710 - Leading and Innovating in Security

TL;DR: This week's podcast features Adam Ely - innovator, leader, and founder. Adam's led some of the world's largest security orgs, and started a tiny start-up. He's got knowledge and wisdom to share, so take it in.YouTube video: https://youtube.com/live/PVTDaiiwlMsHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

June 9, 2026Episode 70915 min

DtSR Episode 709 - Zero Trusting OT

TL;DR: Phillip Wylie joins Rafal live from Zero Trust World 2026 in Orlando, FL, to talk about Operational Technologies (OT) in the context of Zero Trust. As the Joker once said, "Hubba Hubba, who do you trust?"YouTube: https://youtu.be/N5sI85IwxIQHave something to say? Let's hear it.Support the show>>> Please consider clicking the link above to support the show!-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHqLinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/X/Twitter: https://twitter.com/dtsr_podcast

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts