How do you prioritize vulnerabilities based on actual exploitability?

SAST and DAST are flooding our Jira backlog with thousands of "High" and "Critical" findings. We can't fix them all, and the devs are ignoring tickets. I'm looking to implement an Exposure Validation layer that actually validates if a vulnerability is exploitable given the current network controls.

We are looking at a platform that prioritizes based on exploitability using an AI engine. The key difference from traditional SAST/DAST is that it validates whether a vulnerability is actually exploitable given your compensating controls. So you don't waste time patching things that are already protected.

We want to pipe their validation results into our Jira and CI/CD. If the AI determines a vulnerability is not exploitable due to a network control or WAF rule, we are fine to deploy. But if it is exploitable, we want to block the build until it is fixed. The challenge is speed. A full validation sweep might take hours, but our builds run in minutes.

Has anyone actually integrated a validation platform's API to act as a quality gate? Are you running spot checks on critical changes instead of full sweeps? Also, how are you feeding the validation findings back to the developers? The platform can suggest control updates, but developers need to know why their code is vulnerable. Just saying "blocked by validation" isn't helpful.

reddit.com
u/First-Reality2108 — 21 hours ago
▲ 16 r/Splunk

What are the best detection engineering tools for validating SIEM rules?

We have a SIEM with 200+ rules, and 90% are garbage. A validation platform we're looking at promises to use an AI engine to map our SIEM rules to specific attack scenarios and test if they actually fire. It can also generate new detection logic based on emerging threats and manage the full detection lifecycle.

Has anyone used this type of module to automate the creation of new detection logic? I'm specifically interested in how it handles the "tuning" phase. Can it differentiate between a simulation and a real attack, or do we have to manually whitelist it like we do with other BAS tools? I'm looking for something that reduces alert fatigue, not adds to it.

reddit.com
u/First-Reality2108 — 15 days ago

SafeBreach for exposure validation, honest opinions?

I am tired of reviews that sound like they were written straight after a vendor demo and passed off as real evaluations, so I am asking here instead.

We need full stack exposure validation, not only network focused testing. We want to validate WAF rules against injection and bypass techniques, test email security controls against phishing and payload delivery chains, identify detection coverage gaps in our SIEM, and get remediation prioritization tied to actual exploitability. Our team has experience but is small, and we cannot afford to glue together a pile of point tools and hope they form a coherent picture.

SafeBreach keeps landing in our shortlist and i feel their sales team talks a lot without saying much. Claims about MITRE ATT&CK coverage vary a lot between the slide deck and what people report in production. Contract flexibility has also been vague.

If you have deployed them in a real environment, not only a short proof of concept, I would like the straight version. Would you choose them again? What failed? What turned out better than expected? Also open to other platforms if something else gave you better exposure validation and detection coverage.

reddit.com
u/First-Reality2108 — 1 month ago

Detection engineering coverage is way worse than I thought. what am I missing?

I ran a MITRE ATT&CK coverage audit recently and the results were humbling. We had gaps across persistence, defense evasion, and credential access that I did not know existed. Some rules passed review but had never been validated against real adversary behavior.

Right now we write a detection, send it into the SIEM, and then trust it until an incident proves otherwise. Several rules had not fired for a long time and nobody noticed. That is not really a detection engineering program, that is hope with logging.

How do you validate that detections actually fire against realistic techniques without waiting for a live incident to expose the gap? When you discover missing coverage, how do you decide what to fix first when every hole feels urgent?

I am interested in practical approaches that use exposure validation or automated testing rather than building a full in house red team.

reddit.com
u/First-Reality2108 — 1 month ago
▲ 17 r/ciso

Frustrated trying to prove cyber resilience to leadership - need advice

The board is no longer interested in a raw vulnerability count and to be honest I am not either. Each quarter we have the same discussion: here is how many issues we found, here is how many we closed, and then someone asks whether the organization is actually safe.

I do not have a clean answer. The team is working hard, but the metrics we track do not really show whether our controls would withstand a serious attack. I can say our endpoint coverage is in the mid ninety percent range and that mean time to detect has gone down by roughly a third, but that does not tell anyone whether we would catch a ransomware group moving laterally using living off the land techniques. Patch rates and alert volumes describe activity, not resilience.

I have started looking into continuous exposure validation to build reporting that has more weight, for example assessing controls against realistic threat scenarios and showing measurable improvement over time instead of just effort spent. Has anyone here built board level reporting that uses exposure validation and detection coverage data? Which metrics actually made sense to non technical leadership and which ones failed to land?

I would like to hear from other CISOs on how you translate exposure validation results into language that satisfies leadership without dumbing it down too far.

reddit.com
u/First-Reality2108 — 1 month ago
▲ 13 r/Hobbies

What's a hobby you picked up "just to try" that unexpectedly became a big part of your life?

I always find it interesting how some hobbies start as a random weekend experiment and somehow turn into something you stick with for years.

What was yours, and what made it click? I'd love to hear the story behind it, whether it's something common like photography or cooking, or something really niche.

reddit.com
u/First-Reality2108 — 1 month ago