An Introduction to Threat Hunting

In cybersecurity, some of the most interesting work happens outside of responding to alerts or blocking connections. It’s in the quiet work of studying how attackers operate, learning from breaches reported by others, and digging into your own data to uncover things your monitoring tools may have missed. That’s what threat hunting is about: going …

Continue reading An Introduction to Threat Hunting

Windows Forensics: Prefetch 101

While attending the annual Texas Cyber Summit recently, I watched a talk by Marcus Guevara of Recon Infosec titled “The Best Free Resources to Get Started in Incident Response.”  One of the things he mentioned in that talk is Windows Prefetch – something already built into Windows by default. I had never heard of Prefetch …

Continue reading Windows Forensics: Prefetch 101

Introduction to the Volatility Framework

Recently I was very fortunate to be able to attend not only the BSides Austin conference this past weekend, but the two training days immediately preceding it.  One of the training workshops I attended was Incident Response with Volatility Framework, taught by Evan Wagner.  If you ever have the opportunity to attend this training in …

Continue reading Introduction to the Volatility Framework