The Difficulty of Saying Nothing

Like everyone else I’ve been following the tragic war in Ukraine and mourning the loss of life and humanitarian crisis. Professionally as an analyst in the threat intelligence and computer network defense world I’ve been considering what this war and spillover means for defending networks, especially as organizations like CISA keep putting out bulletins regarding threats of Russian nexus adversaries.

March 21, 2022 · 5 min · Scott J Roberts

Crash Override Chronicles: Victim

Victim Sites & Technology So all of those things were term or bits about generalized grid operations.

August 31, 2017 · 2 min · Scott J Roberts
High voltage power lines and electrical infrastructure

The Crash Override Chronicles: Overall

Source: Public Domain Pictures In the first post of the CRASH OVERRIDE Chronicles I outlined my plan for reviewing Dragos’ CRASHOVERRIDE report i…

August 16, 2017 · 8 min · Scott J Roberts
Crash Override report cover page by Dragos

The Crash Override Chronicles

Multi-part analysis series examining the Crash Override attack on Ukrainian electrical infrastructure using the Diamond Model framework.

August 8, 2017 · 3 min · Scott J Roberts

Familiarity Breeds Contempt: APT Edition

The APT hype cycle: how threat groups go from feared to dismissed. Why both over and underestimating adversaries is dangerous.

August 4, 2017 · 7 min · Scott J Roberts
Browser address bar with a URL being entered

The “What happens when you use a browser?” Question

Go into a tech interview, especially one for operations or security, and you’re more than likely going to get an interview question like this. “What happens when you put a URL in the address bar of a browser and hit enter?”.

January 19, 2017 · 12 min · Scott J Roberts
Moscow Kremlin viewed from the river

United States Response to Grizzly Steppe

U.S. government response to Russian election interference: sanctions, IOCs, and diplomatic actions against Grizzly Steppe.

December 29, 2016 · 4 min · Scott J Roberts
Hamilton cast performing on stage at the Richard Rodgers Theatre

Waiting vs Passivity in DFIR

Strategic patience in DFIR: knowing when to wait for intelligence versus taking immediate action, inspired by Hamilton.

December 10, 2016 · 3 min · Scott J Roberts

Python for CND

Learn why Python is the must-have programming language for computer network defense professionals.

November 30, 2016 · 6 min · Scott J Roberts
osqueryi interactive terminal prompt after launching

osquery 101 — Getting Started

Introduction to osquery: Facebook’s SQL-based endpoint monitoring framework for Linux and macOS security.

January 26, 2016 · 4 min · Scott J Roberts