1Q Professional Development Rollup
By: adricnet, In: cybersecurity, education, Tags:Rolling up what could have been February and March updates on courses I’m taking and how my organisations are going.
Jan 2026 Professional Development
By: adricnet, In: cybersecurity, education, Tags:A few notes on my professional development activity in Jan 2026:
SecOps Resources Update
By: adricnet, In: cybersecurity, education, Tags:SecOps Resources Updated (late 2025): free and inexpensive resources for cybersecurity operations leaders
Flash File Systems
By: adricnet, In: cybersecurity, evidence, Tags:Flash talk idea: Filesystems in Cybesecurity Investigations
Job Musings
By: adricnet, In: cybersecurity, threat intelligence, careers, Tags:Here we are thinking by writing about past, current, and future roles and work. Feedback and questions always appreciated!
CTI Report Data Thoughts
By: adricnet, In: cybersecurity, threat intelligence, Tags:Some unfinished ideas and references about what’s useful to cybersecurity defense to and from CTI … leads into the infamous 127.0.0.1 story.
Professional Development Plan 2025
By: adricnet, In: education, Tags:Here again** are some thoughts and links about some of the things we have planned for professional development and education for the year. Feedback appreciated or just share what you are learning!
TIL FOR508 Review 2024
By: adricnet, In: education, Tags:Things I Learned (TIL) FOR508 Review 2024
How Not talk links
By: adricnet, In: education, Tags:How Not… talk: slides and links Herein are some books, articles, and people that we read, skimmed, or thought fondly of while preparing the “How Not to Have a Bad Time with Risky Data” talk seen at B-Sides Atlanta 2024
TIL DFIR Summit 2024 online
By: adricnet, In: education, Tags:TIL DFIR Summit 2024 online
Development Planning 2024
By: adricnet, In: education, Tags:Here are some thoughts and links about some of the things I’m thinking about for professional development and education for the year. Update 1 in early July with some details and “how it’s going”. Update 2 in early Oct with more details and “how it’s going”.
Perfect Threat Intel Report Ideas
By: adricnet, In: cybersecurity, Tags:What would make up the perfect cybersecurity threat intelligence (CTI) report to receive, ingest, automate around? Honestly, even any three of these things makes for a great report. More context and detail are better, if the report author / information sharing organisation can support it.
Getting started in cybersecurity 2023
By: adricnet, In: mentoring, Tags:My recommendations to new folks, mentees, and several Lyft drivers in TL;DR or perhaps BLUF:
Other Interview Questions You Might Ask
By: adricnet, In: mentoring, Tags:Collecting a number of questions that might be informative to ask in job interviews, for practice and mentoring usage. You probably can’t/shouldn’t ask all of these, might not get an answer, and “No” isn’t bad. Deliberately excluded are most compensation and benefits questions which you should definitely ask about. People have different needs and priorities, so getting more information helps everyone make better decisions. Hope this helps!
InfoSec Things with Python
By: adricnet, In: education, Tags:InfoSec Things You Can Do with a little Python
programming experience helpful, but not required
Planning 2022
By: adricnet, In: education, Tags:Some thoughts and links about some of the things I’m thinking about for professional development and education for the year
Mentor Question Personal Branding
By: adricnet, In: careers, Tags:A few thoughts on personal branding, starting with mine/ours here:
TIL SEC564 Red Team Exercises & Adversary Emulation
By: adricnet, In: education, Tags:Things I learned (TIL) and what I got out of the awesome two days SANS course on Red Team and Adversary Emulation I took online after Purple Team Summit 2021
DC404 AMA
By: adricnet, In: education, Tags:I did an AMA with my home hacker club in Atlanta, GA: DC404
Study Plan '21
By: adricnet, In: education, Tags:Nearly half-way through a busy year I think I know what I’m working on … especially after dropping out of college again after trying it again for a couple years. I’m dividing up my time and attention mostly between the two skillsets that I’ve used so far and see myself continuing to use at $dayjob and beyond.
GSE Study Again
By: adricnet, In: education, Tags:Herein are a few notes on my prepping to renew my GSE as traditionally made and posted before taking the exam. I’ll be taking the renewal exam shortly and won’t be able to comment about it. For my backstory try my previous GSE study post (2017) and for more info on GSE see the official site: https://giac.org/gse .
Mailbag VM tools question
By: adricnet, In: education,malware, Tags:From the Mailbag: a VM tools question
A question came in via mail this week: “I see that there is Windows-based security distribution flare-vm. I am wondering the difference between REMnux and flare-vm.
2020 Prof Dev Edu
By: adricnet, In: education,dfir, Tags:2020 Professional Development and Education rollup
Yara Make Your Own Rules
By: adricnet, In: education,dfir, Tags:dc404: 17 Oct 2020 presentation notes and link dump
Fun with [Famous] Malware
By: adricnet, In: education,dfir, Tags:In which yours truly takes REMnux 7 and Ghidra for a spin with some newly famous malware
HNFC Again (Again)
By: adricnet, In: education,dfir, Tags:HNFC Again, Again
Your Infosec Career
By: adricnet, In: education, Tags:Your InfoSec Career, as presented at BSides ATL 2019 @ KSU
Links from Class
By: adricnet, In: education, Tags:Here is a collection of links from class discussions.
Debugging for Attack and Defence
By: adricnet, In: attack, Tags: brownbagDebugging for Attack and Defence: Learning to Attack, a brownbag in the 2018 series.
TIL from Linux/Unix Security
By: adricnet, In: course, Tags: brownbagA few notes about SEC506 and what I learned from it, plus the the start of my exam prep list for GCUX
Reading and Writing the Web
By: adricnet, In: attack, Tags: brownbagReading and Writing the Web: Learning to Attack, a brownbag from the 2018 series
Learning to Attack
By: adricnet, In: attack, Tags: brownbag2018 Kickoff: Learning to Attack
CISSP, PWK, OSCP, or getting started
By: adricnet, In: FAQ, Tags: githubSome good FAQs from mailbox
GIFAR's Magic Mimes Filed in 8 by 3
By: adricnet, In: analysis, Tags: brownbagGIFAR’s Magic Mimes Filed in 8 by 3: File types, identification techniques, and their weaknesses to attack
SANS GIAC Exam Study Tips
By: adricnet, In: education, Tags: brownbagSANS GIAC Exam Study Tips
GSE Study and Prep notes
By: adricnet, In: education, Tags:Herein are a few notes on my journey towards GSE as traditionally made and posted before the exam. For more info on GSE see the official site: https://giac.org/gse
Hunting words
By: adricnet, In: hunting, Tags:Some words about hunting including some perspectives from different sources
Port Proxy detection
By: adricnet, In: Tool, Tags: imported,gistHow can we see port proxy configurations in DFIR?
Netcat practice
By: adricnet, In: Tools, Tags:This morning with much coffee I’m working between email to practice netcat between hosts for GSE, PWK, and generally building good character.
Professional Development and Education 2016
By: adricnet, In: education, Tags: gistSome fairly detailed notes on the classes I taught, took, conferences I attended, fees, and other professional development and education expenses in 2016, for discussion
ARP attack classwork
By: adricnet, In: Network Analysis, Tags: imported, ittamAfter looking at the tables with the MAC address for awhile I looked up the OUI online and substituted them in, hoping to catch something I’d missed. Indeed there was a third MAC from a third manufacturer in the discussion. All three OEMs make network gear as well as endpoint systems.
Email Input
By: adricnet, In: notes, Tags: importedNotes on email-based file submission to analysis platforms
Breakin Into InfoSec
By: adricnet, In: Careers, Tags: imported@adricnet presented this at DC404, Sept 2016 PDF of slides here: http://dfirfiles.net/myslides/breakin_dc404_2016.pdf
Hunting Tips
By: adricnet, In: Security Operations, Tags: importedHunting investigations should be SMART, and more over must have a scope and a terminating condition. Measurement can be simple success/fail (did we find it?) or the number of incidents and/or SIEM/IPS rules generated or updated.
SOC Resources
By: adricnet, In: Security Operations, Tags: importedsome bookmarks
Learn Learning Malware
By: adricnet, In: Education, Tags: imported,studygroupA study group around Practical Malware Analysis, Part I
Home Lab 2016 (2015)
By: adricnet, In: homework, Tags: importeddraft post, no images, end notes, links yet
Secure DOC Email Malware
By: adricnet, In: File Analysis, Tags: importeddraft post, needs more links and images
Emily's Photos
By: adricnet, In: File Analysis, Tags: importedEmily sent me so many copies of this executable in the last couple days that I decided to take a look:
Blacklist Failures
By: adricnet, In: File Analysis, Tags: importedAs I’ve mentioned before one of the things I’m self-studying these days is file analysis. The chosen text is the most excellent Practical Malware Analysis (red with the alien autopsy cover). The authors include lab exercises to demonstrate the analysis techniques from each chapter and they are freely available, so buy a couple copies of the book, such as from the publisher’s site.
Poke Science
By: adricnet, In: Education, Tags: importedHow to Learn About $SYSTEM Security General techniques for developing better understanding about security functions and asserting confidence in them
Learn More Security
By: adricnet, In: Education, Tags: importedDo you want to know more?
Powershells
By: adricnet, In: Tools, Tags: importedA few examples from the major Windows command line tools
GIFAR's Magical Mimes Filed in 8 by 3 (2012)
By: adricnet, In: File Analysis, Tags: imported,brownbagoutline and notes for 2012 file types brownbag
Email EXEs and Free Tools
By: adricnet, In: File Analysis, Tags: importedSince I don’t really want someone else’s pictures and didn’t order anything from FedEx this week so I could safely ignore the odd emails coming in with subjects like “Re:” and “Your package is available for pickup” and zip file attachments. But I’m a curious sort …
Netcat a powerfool tool (2009)
By: adricnet, In: Tools, Tags: importedA fairly high level component to Unix and networking magicks. Not for the novice, much.
Web Sec Quiz (2008)
By: adricnet, In: Web Security, Tags: imported##Linux
Deletion Contest (2001)
By: adricnet, In: Humour, Tags: importedKiddies, don’t try this at $home, a fake contest I wrote up in the fall of 2001
