A bunch of books.

Golang for DFIR

Discover when Go outperforms Python for security tools and how to make the language switch effectively.

July 18, 2016 · 8 min · Scott J Roberts
Squad Goals header image for intelligence requirements setting

CTI SquadGoals — Setting Requirements

Transform vague security concerns into specific, actionable intelligence requirements that drive results.

March 30, 2016 · 6 min · Scott J Roberts
osqueryi interactive terminal prompt after launching

osquery 101 — Getting Started

Introduction to osquery: Facebook’s SQL-based endpoint monitoring framework for Linux and macOS security.

January 26, 2016 · 4 min · Scott J Roberts
iPad and Chromebook as lightweight travel device alternatives

Travel OpSec

Essential operational security practices for international travel including device hardening and threat awareness.

January 20, 2016 · 9 min · Scott J Roberts
T Shaped People

Introduction to DFIR

Comprehensive guide to starting a career in Digital Forensics and Incident Response with practical resources.

January 11, 2016 · 15 min · Scott J Roberts
The Intelligence Cycle diagram with six steps

Intelligence Concepts — The Intelligence Cycle

Explains the Intelligence Cycle’s six steps with hands-on examples from tracking APT groups.

December 16, 2015 · 8 min · Scott J Roberts

Crisis Communications for IR (The Preso!)

In September I wrote about Crisis Communications in Incident Responsehttp://sroberts.

July 8, 2015 · 1 min · Scott J Roberts

FIRST 2015

FIRST 2015 Berlin conference preview with talk recommendations on threat intelligence and incident response.

June 11, 2015 · 6 min · Scott J Roberts
Atom text editor interface with a project open

How I Atom

Personal Atom editor workflow guide with package recommendations and productivity tips for security work.

June 6, 2015 · 5 min · Scott J Roberts
SANS Incident Response Process cycle diagram showing six phases

Intelligence Concepts  -  The SANS Incident Response Process

Deep dive into the SANS Incident Response Process for structured DFIR operations and lifecycle management.

May 18, 2015 · 4 min · Scott J Roberts