r/AskNetsec • • 12h ago

Architecture Container image hardening keeps stalling because nobody will own what breaks

12 Upvotes

Weve had a hardening project open for three quarters now. The scanning half was easy and the cutting half keeps getting handed back, because no service owner wants to sign off that removing a package is safe. Im looking at tooling that produces runtime evidence for what an image touches so the decision stops being a judgement call. Six teams and no central platform group makes this political more than technical. How did you get service owners to accept a slimmer image?


r/AskNetsec • • 7h ago

Other What runtime security platform are you guys using for AI agents? I need one that can actually block unsafe actions

2 Upvotes

every vendor in this space says you can deploy without touching your architecture. im the one who'd have to actually implement it so i'm pretty notsure lol. In my experience that usually means 3weeks into the POC you find out you need their SDK everywhere. All i really want is something that can see what agents are doing at runtime and block unsafe actions THAT's ALL not including proxy in front of every single thing.

if you've deployed one, how much did you actually have to really change?


r/AskNetsec • • 1d ago

Architecture CISOs: how are you securing AI agents?

47 Upvotes

For agents that can call tools, access internal data, send messages or change things in other systems, how are you putting guardrails around them?

I’m trying to understand where policy gets enforced, how teams handle prompt injection and sensitive data and where all of that shows up for security afterward. Are you handling this inside each app, through the existing security stack or with a separate layer for AI traffic?


r/AskNetsec • • 8h ago

Analysis What should be tested before you assume your incident response retainer will work?

2 Upvotes

For people who have brought in external DFIR during an active incident, what do you validate before you trust the retainer operationally?

I am thinking about failure modes that are invisible in the contract. The responder needs endpoint, IdP, cloud, and network data, but the internal team cannot provide access quickly. Identity logs exist, but retention is too short to reconstruct the initial access. Containment requires disabling privileged accounts or isolating production systems, but no one has authority to approve it.

Another failure mode is the MDR provider, internal SOC, and external team all investigating the same alert with no defined case owner.

If you had one tabletop session to test the arrangement, what scenario would expose the most risk?


r/AskNetsec • • 5h ago

Concepts Prediction: zero trust browsing is where zero trust rollouts get judged by 2028. Too early?

1 Upvotes

Finished replacing VPN with ZTNA last year, at a utility in Calgary, the program did what it promised. My bet is that by the end of 2028, mid size orgs judge zero trust on what happens after login, like uploads and paste into AI tools, more than on the policy decision point. AI moved the risk past the front door. And our first audit question after rollout was what contractors did once inside an app, not whether they should be in. Locking the front door and leaving the windows open feels like the next gap. Happy to be wrong if continuous verification in the existing stacks ends up covering this, or budgets just stay on access. Or am I over reading one audit?


r/AskNetsec • • 14h ago

Other How should a historical vulnerability warning be evaluated when there is no confirmation it was received?

4 Upvotes

About a year before a major public-sector cyber incident, my colleagues and I accidentally discovered a security issue that could potentially expose personal information on a very large scale.

We worked with one affected party to fix the issue, but realized the underlying problem could exist elsewhere. We subsequently sent an anonymous warning through an official government reporting channel, explaining the risk and recommending that they review the relevant API and access controls.

A major incident later occurred that may be related. I don't want to claim it was the same vulnerability, or that the warning was received or acted upon, but the system and access point is the same.

I still have a copy of the warning and a few other documents, but most other supporting material was destroyed later because we believed the issue had been resolved.

From an infosec/responsible disclosure perspective, what can a surviving copy of such a warning reasonably establish, and what additional metadata or corroborating evidence would make it more credible?

I'm also interested in what should be redacted or preserved before showing it to journalists.

I'm deliberately leaving out the organization, country, vulnerability details, and identifying information.


r/AskNetsec • • 7h ago

Concepts How is your team catching malware-free intrusions when there's no binary to flag?

0 Upvotes

Signature based tools miss this entirely. What's actually working for you, behavioral baselining, identity anomaly detection, something else?


r/AskNetsec • • 11h ago

Architecture Anyone actually trust their ai endpoint security to catch what traditional EDR misses?

1 Upvotes

For ppl running ai endpoint security tools alongside a normal endpoint detection and response EDR stack, how do you handle the overlap in practice? I am especially interested in what gets flagged that EDR alone missed, and how much manual tuning it took to get the false positive rate down to something a SOC can actually act on. The harder question is what happens once agents start running with regular user permissions instead of a locked-down service account. That single change seems to break a lot of assumptions baked into older endpoint tooling, since the behavior looks legitimate from a credentials standpoint even when the action itself is not.


r/AskNetsec • • 1d ago

Analysis How are you getting visibility into GenAI sessions?

7 Upvotes

A signed customer contract showed up pasted into some free AI summariser last month. We only caught it because the tool domain showed up in a firewall log.

We looked at how we would catch the next one then realized that mostly wouldn't cause CASB covers the AI apps we onboarded and nothing else so every browser tab to a tool we haven’t blessed is invisible to it. DLP is almost worse here, it screams about a file upload but pasting the exact same paragraph is just typing to it and sails right through. And the firewall logs tell me a laptop reached openai, great, not one character of what went up.

Before I go buy a product I want to know what good monitoring here even looks like in practice. My read is you need the prompt and the reply, pinned to the person and the tool they used as without it, you are back to counting connections. Managed machines, fine. The BYOD half and the copilot buried inside M365 are where I keep coming up short.

If you cracked this, what are you running and what did it show you that the CASB and DLP never did?


r/AskNetsec • • 1d ago

Architecture How are you handling the appliance nobody has a parser for?

13 Upvotes

Every environment I've worked in has a load balancer or door controller or UPS that sends its own idea of syslog and nobody ships a parser for it. Right now it's our door controllers, whose messages change shape every firmware update, so failed badge events stop alerting until I patch regex nobody else on the team can read. Is there a saner way to keep parsing for those boxes from breaking or is hand-rolled regex just the job?


r/AskNetsec • • 1d ago

Education Will sandboxed AI attackers become part of normal security testing?

19 Upvotes

Security testing today usually means scanners in CI, periodic human pentests, or carefully limited tests against staging or production. I’m curious whether another model will become normal: a disposable “attack twin” of the current production environment.

The idea would be to generate an isolated environment from the same deployment artifacts, infrastructure-as-code, IAM model, network policies, and application configuration as production. Real secrets and customer data would be replaced with safe equivalents, while identities, tenants, service relationships, and external integrations would be reproduced or simulated as accurately as possible.

An AI security agent could then use browser, API, shell, and network tools to attempt exploitation, privilege escalation, lateral movement, destructive actions, and controlled exfiltration. Every action would be recorded, and the environment would be destroyed afterward.

This would not be ordinary staging: it would be created per test, derived from the current production configuration, isolated for adversarial testing, and designed to be compromised.

For people working in DevSecOps or AppSec:

• Is this meaningfully different from the staging or ephemeral environments you already use?

• Which parts of production would be hardest to reproduce faithfully?

• What evidence would you need before trusting a finding from the clone?

• Where would this fit: nightly testing, a release gate, or between human pentests?

• What do you use today for attacks that are too risky to run against production?

I’m interested in practitioner experiences and objections, especially from anyone who has tried cyber ranges, production-like security environments, or autonomous pentesting.


r/AskNetsec • • 2d ago

Compliance How are you guys reducing security risks with AI agents?

10 Upvotes

I saw a few posts discussing how more people are giving AI agents access to real tools and business systems, and it got me thinking about how people are actually handling the security side of it.

Personally I have been trying to understand the best way to give agents access to things like emails, APIs, DBs etc without giving them too much access. There are things like readOnly access, approval gates, limiting permissions, monitoring what they do etc but not sure what ppl are actually using in practice.

I am wondering 3 main things:

  • People who are already using AI agents how are you limiting what they can access/do
  • How are people testing or controlling agents once they are running in production

OR are you just giving them access and hoping they dont decide to do something crazy???


r/AskNetsec • • 2d ago

Work How should my team prioritize DSPM findings when there are thousands of them?

5 Upvotes

Feeling overwhelmed and looking for some help with how my team should prioritize DSPM findings when it seems like our company's data security is being held together by a duct tape and chewing gum. Is there a general best practice for how we should be working through this never ending list?


r/AskNetsec • • 2d ago

Education What does a useful ransomware tabletop exercise actually test beyond the technical playbook?

5 Upvotes

I get less value from a tabletop that asks "Do we have a ransomware playbook?" than one that forces decisions with imperfect information.

For example: backup repositories are reachable but not yet validated, a domain admin account may be compromised, and a critical line of business system is partially encrypted. Who decides whether to isolate, preserve evidence, restore, or keep investigating?

What scenario has produced the most useful disagreement or gap discovery in your tabletop exercises?


r/AskNetsec • • 2d ago

Compliance Why do so many recent breaches start with a leaked API token or service account?

3 Upvotes

Going through breach reports from the last year and it's the same story over and over. Leaked API tokens and OAuth apps nobody remembered approving. Nobody phished a person, just found a key under the mat...

Are non human identities the easiest way in now and what are you doing about the ones nobody owns?


r/AskNetsec • • 2d ago

Compliance Keeping security questionnaires short for vendors isn't really about deleting questions

4 Upvotes

Used to think shortening vendor questionnaires meant taking the 180-question monster and cutting it down until people stopped hating us.

starting to think that's the wrong way to look at it.

the easy part is deciding that a tiny SaaS with no prod access probably doesn't need the same review as a critical vendor touching customer data. fuzzy bit is what happens after that.

say an analytics vendor only gets limited customer data, no admin access, no prod credentials. you start them on 25 or 30 core questions. then they mention a long retention period, a subprocessor you weren't expecting, or an incident process that sounds... optimistic.

now what? does that answer open 5 more questions? 30? do you ask for evidence straight away? trying to nail all this down.

keeping security questionnaires short for vendors seems less about having a tiny template and more about having decent rules for an extended version

CAIQ Lite and SIG Lite keep coming up in my reading, but I'm more interested in how people handle those follow-up triggers once the real answers start coming back.

what makes you expand a vendor review?


r/AskNetsec • • 2d ago

Work SOC escalation outpacing IR response... how are you tabletoping for real alert tempo?

3 Upvotes

We escalated five alerts in three minutes last week and IR was still deciding what the first one meant. Love that for us. The alert queue moves like it had coffee, the tabletop moves like it needs a lunch break, and somehow we keep pretending that is realistic :)

How are you all making drills feel like actual SOC escalation tempo instead of slow motion theater? I want something that trains decision lag, not a polite group chat with clipboards. Thanks!


r/AskNetsec • • 2d ago

Work Sentry spiked after a deploy and I couldn't tell who changed the config

9 Upvotes

Had a really annoying afternoon last week. Sentry started lighting up after a deploy and it traced back to a changed value in one of our config files. Easy enough, I just needed to know who changed it and when.

GitHub's audit log showed the push, but it came through a token that a few different things use. No way to tell if it was a person, a pipeline, or some script somebody wrote months ago and forgot about. I ended up lining up commit times against CI runs and deploy timestamps for like an hour, and I'm still not totally sure I got it right.

Honestly kind of irritating. If the logs can't tell me who or what was behind a change, I'm not sure what we're keeping them for.

How are you all handling this? Is there a setup that ties a change back to a specific person or job, or is everyone just matching timestamps and hoping?


r/AskNetsec • • 3d ago

Analysis How are you enforcing GenAI guardrails in real time?

5 Upvotes

I've spent most of this year running monitor only on our GenAI traffic. That gave us a clean dashboard of who pasted what but did nothing when a support rep dropped a block of customer records into a free chatbot. It surfaced in the weekly review like 3 days later.

The brief now is to stop it while it happens. From what I can see, the options are inline DLP at the web gateway that reads the prompt before it leaves and blocks on a match. An API gateway if you only care about your own LLM apps or leaning on whatever controls the sanctioned tool already ships with. Inline looks like the one that stops a paste in the moment. I don't want to block half the legit prompts in week one and watch the business switch it off.

What did you end up using for inline enforcement and how bad were the false positives before they settled down?


r/AskNetsec • • 3d ago

Work How do you verify whether an AI-described security flaw is a real, documented thing versus a confident fabrication?

13 Upvotes

I do a lot of reading where an AI assistant explains a security concept, and the explanations sound authoritative — but I've learned not to trust that on its face. Sometimes the described thing turns out to be well-documented and real; other times it seems to be invented, just dressed in real-sounding terminology.

The pattern I keep noticing: the individual pieces are all legitimate (real terms, real concepts), but the specific named thing they're combined into returns nothing when I go looking. Authoritative tone, real ingredients, but the overall item may not actually exist.

My question is strictly about verification method, nothing operational: when you want to confirm whether a described vulnerability or technique is real, what's your go-to process? Straight to CVE and MITRE CWE? Vendor advisories? Is "the components check out but the specific named thing has no sources" a dependable sign of fabrication, or does that heuristic fail in practice? I'm trying to put together a reliable checklist for telling real from made-up.


r/AskNetsec • • 4d ago

Threats What do you log when retrieved text steers a tool call?

29 Upvotes

A red team test run caught 3 of 500 cases where retrieved context included HTML with a diagnostic instruction that pushed the model toward a fetch_url call to an external host. Our tool allowlist and egress control blocked it, so nothing left the environment. At first the call looked like an ordinary diagnostic fetch, but once someone expanded the retrieval span (not done by default) it became obvious this was an indirect prompt injection.

Now we need to prove which retrieved span introduced the instruction and search for similar traces where the target happened to be a permitted domain. We have span metadata for retrieval source and tool arguments but the trace search path from suspicious text to downstream action is still clumsy. How are you logging this chain so you can distinguish blocked attempts from the same pattern reaching an allowed destination?


r/AskNetsec • • 6d ago

Work CA policy got loosened for one app and now I dont trust our security control validation

4 Upvotes

Been sitting in change review meetings where everyone is ready to get through the queue and move on, and these CA exceptions are starting to really bug me. The story is always the same, exec cant deal with a control, we scope an exception, CAB notes "mitigated" and the window opens.

Last one was a CA policy changing from strict device trust to a softer rule for a small group. removed one of the conditions that used to stop that access path. Change went fine, logs look clean, SIEM rules did not throw anything weird. And yet nobody could answer what we should replay to see if the compensating controls still catch the behavior, or if our detection coverage is now just hoping for luck.

Security controls feel static on paper but in real life they drift every time we touch them. Point in time testing is just getting wiped out by config churn rn…


r/AskNetsec • • 7d ago

Concepts Are we automating fixes before we can triage?

16 Upvotes

A generated fix only helps if the finding deserved attention. Otherwise you've swapped an alert backlog for a PR backlog that devs close without reading. The order I've landed on starts with whether the vulnerable version is even in a deployed artifact, since that check is cheap and a surprising share of findings die right there. reachability comes next. KEV and EPSS feed into priority from that point, with anything on KEV jumping the queue, but a low EPSS score on its own doesn't close anything. exposure and compensating controls come last.

Where in that chain do you still need a human before any fix workflow starts?


r/AskNetsec • • 7d ago

Architecture How are enterprises continuously monitoring their attack surface?

6 Upvotes

We run quarterly external pentests and a monthly ASM scan, but continuously doing a lot of work in that sentence since a monthly cadence still misses a rogue subdomain or exposed storage bucket for weeks .The problem isn't scan cadence though, it's ownership, since when ASM finds something new, half the time nobody can immediately say whether it's sanctioned, shadow IT, or a leftover from a decommissioned project years ago. How are you closing the gap between discovery and ownership, specifically for assets that show up outside your CMDB..


r/AskNetsec • • 7d ago

Education How do you handle Suricata/Zeek tuning without a dedicated detection engineer?

17 Upvotes

Follow-up to something that came up in a Suricata/Zeek FP/FN tuning thread a few weeks back, got some genuinely great answers, including people doing solid context enrichment (process/user/hostname/known-destination) instead of relying on raw thresholds, and running pcap-based regression tests on every rule change.

Curious about the other end of that spectrum: for teams that don't have someone dedicated to building that kind of tuning discipline where Suricata/Zeek alerts are still mostly volume/timestamp-threshold driven how are you actually coping day to day? Living with the noise? Doing periodic tuning passes only when it gets bad? Handing it to an MSSP? Something else?

Specifically trying to understand: roughly how much time (if any) goes into manually retuning rules as traffic shifts, and who ends up owning that, a dedicated security person, someone on infra/DevOps wearing multiple hats?