Super timelines with Splunk

I have always been a great fan of Splunk  for analyzing log data when investigating incidents.  One of the downfalls is that while Splunk does a wonderful job searching logs, the timeline it creates is missing critical time information about …..

Read More

Thoughts on Penetration Testing

I’ve watched our industry slowly mature itself over the last fifteen years, and I am still somewhat bemused regarding penetration testing.  It seems like every standard now requires a penetration test to be done, why?  I struggle to see the …..

Read More

Catapulting Corpses

In warfare, as you modify your defenses, your enemy modifies their tactics. This same process of threat evolution is occurring at a rapid pace in the online world. Warfare is not a new endeavor and old tactics are reused in …..

Read More

The Three Ps of Incident Management

When building an incident management capability, the 3P’s, Planning, Preparation, and Practice, are the foundational components of effective incident management.  With out all three Ps, costly mistakes will occur, making success difficult at best, and failure almost inevitable.  2014 has …..

Read More