So you want to be a SANS facilitator.

So you have been chosen to be a SANS Facilitator for your first SANS class. Wondering what to expect, I will give you the inside scoop, to this unique way to experience the SANS experience. Being A Facilitator: You will arrive a couple of days before the event, this largely …

The Autopsy of the PHOENIX X36 Hemodialysis System

I have recently received DD images of data contained in the Phoenix Hemodialysis machine. I wanted to be able to create a baseline of the information which is stored on the storage. The reason this is very important is that in DFIR we want to know what is normal to …

Behind The Incident – Episode 6 : Adam Harrison

Last year in Prague I met the coin slayer Adam Harrison. He was presenting his work on ExFAT forensics and the discrepancies on how forensic tools would parse these dates. Soon I started following his work and found him a comedian of sorts. In this episode, he shares some of …

Behind The Incident – Episode 4 : BlakDayz

I met BlakDayz in an interview for a position. The interviews turned into much of a discussion into DEF CON and not much surrounding the new job. We had such a good time during the interview that we opted to continue our conversation on camera and in real life. Blak, …

Behind The Incident – Episode 2 : Jake Williams

In this second episode, I speak to Jake Williams otherwise known as Malware Jake. I have been following him for some time on Twitter and enjoyed reading these posts. When I had the opportunity to meet him I jumped at the chance. He shares some of his favourite Incidents and …

SRUM Forensics … Say WHAT?

I was asked in 2018 to be on Paul’s Security Weekly also referred to as Hack Naked. Let me be frank, I had no idea what I was getting myself into. I am often someone that says yes to most things at least once. I would say yes again. This …