Squad Goals header image for intelligence requirements setting

CTI SquadGoals — Setting Requirements

Transform vague security concerns into specific, actionable intelligence requirements that drive results.

March 30, 2016 · 6 min · Scott J Roberts
T Shaped People

Introduction to DFIR

Comprehensive guide to starting a career in Digital Forensics and Incident Response with practical resources.

January 11, 2016 · 15 min · Scott J Roberts
The Intelligence Cycle diagram with six steps

Intelligence Concepts — The Intelligence Cycle

Explains the Intelligence Cycle’s six steps with hands-on examples from tracking APT groups.

December 16, 2015 · 8 min · Scott J Roberts

FIRST 2015

FIRST 2015 Berlin conference preview with talk recommendations on threat intelligence and incident response.

June 11, 2015 · 6 min · Scott J Roberts
F3EAD cycle diagram showing Find Fix Finish Exploit Analyze Disseminate

Intelligence Concepts — F3EAD

F3EAD methodology: combining military operations with intelligence cycles for effective incident response.

March 24, 2015 · 4 min · Scott J Roberts
Maltego graph visualization interface showing entity relationships

Maltego Transforms for the Lazy

Step-by-step guide to building custom Maltego transforms with Python examples and automation tips.

March 3, 2015 · 6 min · Scott J Roberts

APT is a Who not a What… And Why it doesn’t Matter

A small number of topics get intelligence driven incident responders incredibly frustrated. Using intelligence to mean smart (I’ll share more about that later this week).

February 16, 2015 · 5 min · Scott J Roberts
OODA Loop diagram showing Observe Orient Decide Act cycle

Intelligence Concepts - OODA

Understanding the OODA Loop for faster incident response and security decision-making cycles.

January 27, 2015 · 4 min · Scott J Roberts
Dark silhouette of a hooded hacker at a computer

The Perils of (Mis)Attribution

The challenges of cybersecurity attribution: incomplete data, easy spoofing, and avoiding bias in threat analysis.

January 4, 2015 · 10 min · Scott J Roberts
Hubot chatbot interface showing ChatOps workflow in action

Using Robots to Fight Bad_Guys

ChatOps for DFIR: Using Hubot to automate security operations through chat interfaces and GitHub workflows.

May 14, 2014 · 5 min · Scott J Roberts