Category: Uncategorized

  • Trump Killed CVE

    The Common Vulnerabilities and Exposures (CVE) program is THE way security professionals track and discuss vulnerabilities. Every business uses CVEs to protect their systems and your data. Killing the CVE program will cripple the ability of professionals to track vulnerabilities and keep your data safe. This decision is incredibly short sighted and tragic. The loss…

  • Make Plans to VOTE NO TOMORROW March 29th!

    Make Plans to VOTE NO TOMORROW March 29th, 2025

  • Nazi's Don't Matter

    Nazis Don’t Matter

    If 9 people sit down at a table with 1 Nazi without protest, there are 10 Nazis at the table

  • NOLACon’s Schedule is Online

    The schedule is up. Check out NOLAcon at the New Orleans Hyatt and come see me on May 18th!

  • Happy Mardi Gras

    Happy Mardi Gras

  • SANS SEC541 Cloud Security Threat Detection

    My thoughts and impressions of SEC541: Cloud Security Threat Detection by SANS 

  • Vote NO on them ALL

    Louisiana Ballot Measure Guide for March 29th 2025

    Louisiana Ballot Measure Guide for March 29th 2025 Vote NO on them all!

  • Speaking at NOLACON!!!

    I was accepted to speak at NOLACON in New Orleans, LA on May 16-18, 2025

  • Banshee Motorclub

    I tried to watch Krewe of Tucks today. Alas I ran into a bunch of Nazis. My friend was riding sidewalk side, so I crossed Napoleon and setup at Ms Maes. I noticed a lot of guys in motor club leather. No problem. Most bikers are cool. This was the Banshee Motor Club. At least…

  • Cache Your Threat Intel Queries

    Security Operations Centers (SOCs) live on automation and threat intelligence. It’s common to lookup every login IP address to determine if it’s known malicious. And analysts want each indicator of compromise (IOC), like IPs, hostnames, URLs, and hash in an alert to be enriched. If the IOC is known bad, highlight it. Modern SIEMs, like…

  • Secure Your Apple Device Now

    Apple products are fairly secure by default, but there a few best practices that can take your Operational Security (OPSEC) to the next level. These are quick and easy steps that make your MacOS and iOS devices much more secure. If you’re security conscious or worried about your privacy:

  • How to Use the Internet Privately

    Online privacy is hard. The Internet is built to identify who you are. It is nearly impossible to use the Internet anonymously. I have over 20 years in cybersecurity. I’ve written network monitoring software, performed countless forensic responses, and executed numerous tailored offensive security operations with complete anonymity. In this post I’ll share a cheap…

  • Imposter Detection with Watchman

    At Shmoocon 2025, I released Watchman – a system to detect imposter domains by diffing ICANN CZDS Zonefiles and running matches. You can see my presentation here.

  • Office 365 Phishing with Password Protection

    Every business sees invoice scams. Most modern email security stacks have automated link analysis and tools to report phishing. A common tactic is to bury a link in a PDF or document. But email security systems can easily process common file formats, enumerate the links, and check each one. Attackers always adapt to overcome security…

  • How Domain Brand Detection Works

    Domains that look similar to known organization are often used in phishing attacks and business email compromise (BEC) scams. Many cybersecurity companies offer brand monitoring and threat intelligence products to detect infringing (scam) domains. Nearly all brand detection products utilize root zone files as a core component. This blog post details how security firms obtain…

  • Protect Your Privacy on MacOS

    In the age of surveillance capitalism, privacy has never been more important. With a little work, you can make major privacy gains.