← Back to list

The Three-Headed Dog Is Asleep.

The content in this article is written for educational purposes only and is to be practiced with consent. No material is to be replicated…

David O'Neill · 2026-08-02 23:29 · 0 claps · 2.3 min read
#detection-engineering #penetration-testing #incident-response #cybersecurity #social-engineering
Open on Medium ↗
Wiki topics: EDU · Education & Learning 🔒 · Cybersecurity 💪 · Fitness & Wellness 💭 · Philosophy of Spirit

The Three-Headed Dog Is Asleep. Now What? A Detection Engineer, Incident Responder, and Penetration Tester Perspective on External Attack Surface

Photo by Hannah jones on Unsplash

Photo by Hannah jones on Unsplash

The content in this article is written for educational purposes only and is to be practiced with consent. No material is to be replicated without consent, other than to further the protection of cybersecurity postures and to support the broader community.

Article was written by human. Grammar supported by AI.

In 2026, security solutions are becoming stronger than before, and the reason is that the bad guys continue their creative tactics to bypass every solution and extract data or disrupt a company. Incident responders are the first line of defense and serve a very important role to responding, containing and recovering from attacks. Detection engineers are important for finding gaps in an environment that traditional SIEM rules cannot detect. Penetration testers are just as important for finding vulnerabilities in systems and networks before threat actors do. Combined, penetration testers, incident responders, and detection engineers are the three-headed guard dog any attacker wants to avoid. These three cybersecurity professionals can guard a company better than any standalone tool, or than a whole team of each working independently of one another.

Initial Access

The strength of any security posture depends first and foremost on blocking threat actors from entering or attacking companies. Once a company is initially breached and the breach goes undetected, that is when havoc begins. Let the havoc be tamed with a stronger perimeter. Firewalls, identity protections, email security, security awareness training, and hardened external systems with endpoint protections are a good start, but what about the fact that all of these have a single point of entry and failure combined in one — the human. Humans might be a brilliant specie, but unfortunately they can be easily manipulated. The weakness.

Performing reconnaissance on the employees of a company across social media and other online platforms to gather public data on individuals, then pairing that knowledge with combined tactics, leads to a successful entry. New sales or marketing employees who are onboarding to a company are prime targets. Using smishing on unmanaged phones will bypass most email, browser, network, and security awareness training and security technologies. Now combine smishing with vishing — a concerned and hardworking “IT” employee trying to help the new hire get set up — and it will lead to a high rate of success. When is the last time a sales agent said no to a hello? Or a marketing person passed on making their device(s) more appealing? Hence, the weakness. However, not all companies are the same. A mature enterprise with a large cybersecurity budget will have identity protections in place. Therefore, the reconnaissance phase will help lead to bypassing that detection. Knowing the phone model, version, city, and the coffee shops or public areas the employee commonly logs in from will allow the entry to be quiet and swift.

The biggest point of failure from an attacker’s perspective is setting off the identity protection technology. Know the person’s habits well enough to replicate them, and the chances of a successful bypass are high. Depending on the risk tolerance of a company and how progressed its cybersecurity posture is, entry might be awarded with a red carpet. Enter, recon, and set persistence in place.

Not all entries are created equal, and neither are detections.


메타데이터
post_id
3efd75ad1d92
slug
the-three-headed-dog-is-asleep-3efd75ad1d92
url
https://medium.com/@david-oneill-4444/the-three-headed-dog-is-asleep-3efd75ad1d92
canonical_url
https://medium.com/@david-oneill-4444/the-three-headed-dog-is-asleep-3efd75ad1d92
author_url
https://medium.com/@david-oneill-4444
status
ok
fetched_at
2026-08-03 18:15:54