The Difficulty of Saying Nothing

Like everyone else I’ve been following the tragic war in Ukraine and mourning the loss of life and humanitarian crisis. Professionally as an analyst in the threat intelligence and computer network defense world I’ve been considering what this war and spillover means for defending networks, especially as organizations like CISA keep putting out bulletins regarding threats of Russian nexus adversaries.

March 21, 2022 · 5 min · Scott J Roberts

Crash Override Chronicles: Victim

Victim Sites & Technology So all of those things were term or bits about generalized grid operations.

August 31, 2017 · 2 min · Scott J Roberts

The Crash Override Chronicles: Overall

Source: Public Domain Pictures In the first post of the CRASH OVERRIDE Chronicles I outlined my plan for reviewing Dragos’ CRASHOVERRIDE report i…

August 16, 2017 · 8 min · Scott J Roberts

The Crash Override Chronicles

Multi-part analysis series examining the Crash Override attack on Ukrainian electrical infrastructure using the Diamond Model framework.

August 8, 2017 · 3 min · Scott J Roberts

Familiarity Breeds Contempt: APT Edition

The APT hype cycle: how threat groups go from feared to dismissed. Why both over and underestimating adversaries is dangerous.

August 4, 2017 · 7 min · Scott J Roberts

The “What happens when you use a browser?” Question

Go into a tech interview, especially one for operations or security, and you’re more than likely going to get an interview question like this. “What happens when you put a URL in the address bar of a browser and hit enter?”.

January 19, 2017 · 12 min · Scott J Roberts

United States Response to Grizzly Steppe

U.S. government response to Russian election interference: sanctions, IOCs, and diplomatic actions against Grizzly Steppe.

December 29, 2016 · 4 min · Scott J Roberts

Waiting vs Passivity in DFIR

Strategic patience in DFIR: knowing when to wait for intelligence versus taking immediate action, inspired by Hamilton.

December 10, 2016 · 3 min · Scott J Roberts

Python for CND

Learn why Python is the must-have programming language for computer network defense professionals.

November 30, 2016 · 6 min · Scott J Roberts

osquery 101 — Getting Started

Introduction to osquery: Facebook’s SQL-based endpoint monitoring framework for Linux and macOS security.

January 26, 2016 · 4 min · Scott J Roberts