
Travel OpSec
Essential operational security practices for international travel including device hardening and threat awareness.

Essential operational security practices for international travel including device hardening and threat awareness.

Comprehensive guide to starting a career in Digital Forensics and Incident Response with practical resources.
FIRST 2015 Berlin conference preview with talk recommendations on threat intelligence and incident response.

Deep dive into the SANS Incident Response Process for structured DFIR operations and lifecycle management.

Confronts impostor syndrome in DFIR with real experiences and actionable advice for overcoming self-doubt.

Key open source tools that enable proactive threat hunting including osquery, ELK, and Moloch.

Talk to anyone in the DFIR Illuminati and one of the topics that always comes up is Hunting.
A small number of topics get intelligence driven incident responders incredibly frustrated. Using intelligence to mean smart (I’ll share more about that later this week).

The challenges of cybersecurity attribution: incomplete data, easy spoofing, and avoiding bias in threat analysis.

One part of intrusion response that rarely gets enough attention in DFIR circles is the communications victim companies make to their own customers.