The Crash Override Chronicles: Overall

Source: Public Domain Pictures In the first post of the CRASH OVERRIDE Chronicles I outlined my plan for reviewing Dragos’ CRASHOVERRIDE report i…

August 16, 2017 · 8 min · Scott J Roberts

The Crash Override Chronicles

Multi-part analysis series examining the Crash Override attack on Ukrainian electrical infrastructure using the Diamond Model framework.

August 8, 2017 · 3 min · Scott J Roberts

Familiarity Breeds Contempt: APT Edition

The APT hype cycle: how threat groups go from feared to dismissed. Why both over and underestimating adversaries is dangerous.

August 4, 2017 · 7 min · Scott J Roberts

CTI Reading List

A few weeks ago while teaching SANS FOR578 one of my students asked a great question by a student: What books or papers should a new cyber threat i…

July 18, 2017 · 7 min · Scott J Roberts

The “What happens when you use a browser?” Question

Go into a tech interview, especially one for operations or security, and you’re more than likely going to get an interview question like this. “What happens when you put a URL in the address bar of a browser and hit enter?”.

January 19, 2017 · 12 min · Scott J Roberts

United States Response to Grizzly Steppe

U.S. government response to Russian election interference: sanctions, IOCs, and diplomatic actions against Grizzly Steppe.

December 29, 2016 · 4 min · Scott J Roberts

ACH Analysis of a Trump Campaign Compromise

This post gets political. People may agree or disagree based on their own experience or personal belief.

December 12, 2016 · 10 min · Scott J Roberts

Waiting vs Passivity in DFIR

Strategic patience in DFIR: knowing when to wait for intelligence versus taking immediate action, inspired by Hamilton.

December 10, 2016 · 3 min · Scott J Roberts

Python for CND

Learn why Python is the must-have programming language for computer network defense professionals.

November 30, 2016 · 6 min · Scott J Roberts

Intelligence Collection Priorities

Strategic framework for prioritizing threat intelligence collection from internal data to commercial feeds.

November 23, 2016 · 5 min · Scott J Roberts