This is kind of weird advice but it’s important:
Don’t let the moment you show someone they’re professionally appreciated and you’re willing to help them do awesome new stuff be at their exit interview or early retirement. Even if you assume Everything Is Fine and never check in.
Then, when they have resolved to go? It is too late. They have made the difficult decision to go from your company or volunteer org or club. They are so very rarely going to rethink that decision or even be able to.
If you’re a manager or director you need to have candid conversations about what is causing your people to not succeed. If you’re like “hey, here is a cool thing this person could help with” the time is TODAY, because tomorrow they will assume you didn’t care enough to ask.
I have personally received some of the most stellar, cool offers in my entire career after deciding after months to stop volunteering at an org, or leave a job, or stop consulting with an group. And they’re like “bUt YoU’rE aN iNfluEncEr.” And I’m like, “but you never asked…”
It is so very frustrating. In personal and professional life, sometimes you have to just OFFER.
• • •
Missing some Tweet in this thread? You can try to
force a refresh
If you’re angry for no reason you’re burnt out,
If you’re sleepy for no reason you’re burnt out,
If you’re irrationally mad and your work suddenly looks bad,
Spontaneously apathetic you’re burnt out.
*This is not a clinical diagnosis, and please seek prompt and professional treatment for mental health concerns
But seriously, take a vacation, have an actual meal at a table, and reconsider your work life balance.
Lot of people asking how to gain forensics skills right off the street now. I got myself into this 🤷🏻♀️🍸. Best way to start to learn forensics is to *do it on your own Windows computer* (preferably physical). Start with basic sysinternals tools. @markrussinovich’s books are great.
You have a handy piece of evidence to examine right in front of you, and understanding how your own activity appears in memory, registry, caches, and MFT can often be much more memorable and educational than some VM lab. Lots of great free Windows forensics tools out there.
The tools we use day to day to do memory forensics are widely free, like Volatility. Disk forensics is still kind of controlled by a few expensive software powerhouses, but just learning how your own computer stores, processes, executes is a huge educational leap forward.
Hey, so I want to talk about something that riles up or disheartens a lot of jr cybersecurity people and raises questions about gatekeeping, my perspective, and why I don't think it's as catastrophic as it looks from the outside. It has to do with experience required to do IR.
There is this unwritten set of rules that are constantly bandied about by senior DFIR people, and they go something like this:
"To do IR, you need 1-2 years of experience in cybersecurity (usually SOC)"
&
"To lead IR engagements you need 1-2 years of experience in DFIR"
OK, so is this gatekeepy? If you make it a static part of your hiring process, probably. Is it a bad guideline? No, and that's not so bad.
Let's talk about what Digital Forensics and Incident Response (DFIR) entails.
I love @SouthwestAir *tons*, but flying into O’Hare instead of Midway is an awful experience. One baggage carousel for all flights in the crowded international arrivals, and not even anywhere to get a bottle of water while waiting after McDonalds closes. Midway is so much nicer…
Terminal 5 rideshare pickup is free for all chaos, too 😢😑
I don’t get people who bash Midway. It’s a really nice and manageable airport since the refurb. Great food, too.
Sometimes instead of blogging I feel like making a big old Twitter thread, so let's talk about Cobalt Strike for people only vaguely familiar (or misinformed) with the concept. Maybe I'll blog it later.
Cobalt Strike is an adversary enumeration tool used to train teams how to do incident response and threat hunting. It was made by a genius I genuinely like and will not disparage, Raphael Mudge. The first time I met him he flew across the floor air-guitaring in his dress clothes.
A lot of you are familiar with the easy-button hacking tool, Metasploit. Well, he made this shnazzy GUI for Metasploit called Armitage.
But, he realized it was still tough for a lot of defenders to get highly skilled Red Teams to train them. Or sommat, I'm not in his head...