iPad and Chromebook as lightweight travel device alternatives

Travel OpSec

Essential operational security practices for international travel including device hardening and threat awareness.

January 20, 2016 · 9 min · Scott J Roberts
T Shaped People

Introduction to DFIR

Comprehensive guide to starting a career in Digital Forensics and Incident Response with practical resources.

January 11, 2016 · 15 min · Scott J Roberts

FIRST 2015

FIRST 2015 Berlin conference preview with talk recommendations on threat intelligence and incident response.

June 11, 2015 · 6 min · Scott J Roberts
SANS Incident Response Process cycle diagram showing six phases

Intelligence Concepts  -  The SANS Incident Response Process

Deep dive into the SANS Incident Response Process for structured DFIR operations and lifecycle management.

May 18, 2015 · 4 min · Scott J Roberts
sroberts replacement box

Imposter Syndrome in DFIR

Confronts impostor syndrome in DFIR with real experiences and actionable advice for overcoming self-doubt.

May 2, 2015 · 7 min · Scott J Roberts
Google Rapid Response GRR interface for remote live forensics

Incident Response Hunting Tools

Key open source tools that enable proactive threat hunting including osquery, ELK, and Moloch.

April 21, 2015 · 5 min · Scott J Roberts
Duckhunt!

Incident Response is Dead… Long Live Incident Response

Talk to anyone in the DFIR Illuminati and one of the topics that always comes up is Hunting.

April 13, 2015 · 6 min · Scott J Roberts

APT is a Who not a What… And Why it doesn’t Matter

A small number of topics get intelligence driven incident responders incredibly frustrated. Using intelligence to mean smart (I’ll share more about that later this week).

February 16, 2015 · 5 min · Scott J Roberts
Dark silhouette of a hooded hacker at a computer

The Perils of (Mis)Attribution

The challenges of cybersecurity attribution: incomplete data, easy spoofing, and avoiding bias in threat analysis.

January 4, 2015 · 10 min · Scott J Roberts
Mark Imbriaco example of effective incident post mortem communication

Crisis Communication for Incident Response

One part of intrusion response that rarely gets enough attention in DFIR circles is the communications victim companies make to their own customers.

September 22, 2014 · 7 min · Scott J Roberts