Finding Initial Access
Brief
I recently ran across a comment from a SOC manager on social media that said, "Finding initial access is difficult."
I thought about it for a moment, and had to ask, "why is that?"
For context, I transitioned from military service in 1997, and shortly thereafter, was running vulnerability assessment engagements, leading teams on-site to do the work, and completing reporting to the customer. I did "war dialing" (which was a lot of fun), and full-on, enterprise-wide data collection as part of overall vulnerability assessments.
I then transitioned into DF/IR work, doing both consulting and FTE work, and I've also worked as a SOC analyst, and even run an internal, global SOC for a while.
