chrissanders88 Profile Banner
Chris Sanders πŸ”Ž 🧠 Profile
Chris Sanders πŸ”Ž 🧠

@chrissanders88

Followers
33K
Following
16K
Statuses
15K

Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM

Mayfield KY ➑️ Gainesville GA
Joined July 2008
Don't wanna be here? Send us removal request.
@chrissanders88
Chris Sanders πŸ”Ž 🧠
2 years
Hi, Y'all! I tweet about the intersection of cyber security investigation doctrine, cognitive psychology, and education. Also BBQ. πŸ‘¨πŸ»β€πŸ« Online Courses I Teach: πŸ“š Books I've Written: 🌎 Blog & More Links:
7
32
108
@chrissanders88
Chris Sanders πŸ”Ž 🧠
17 minutes
RT @chrissanders88: It's a bit tangential to what I do here, but I've been making some short-form video content focused on Meteorite educat…
0
1
0
@chrissanders88
Chris Sanders πŸ”Ž 🧠
47 minutes
I’ve always thought these SSH tunneling techniques were confusing to follow at times, but Dan does a tremendous job simplifying the idea. Lots of practical demos. A must understand for attackers and defenders, both.
@NetworkDefense
Applied Network Defense
1 hour
In our newest Skills Vault lesson, Dan Marr demonstrates network traversal and lateral movement techniques with SSH tunneling and then walks through evidence artifacts left by these actions.
Tweet media one
0
0
8
@chrissanders88
Chris Sanders πŸ”Ž 🧠
16 hours
It's a bit tangential to what I do here, but I've been making some short-form video content focused on Meteorite education. If you're into that sorta thing, you can watch here: Youtube: Instagram: TikTok:
0
1
0
@chrissanders88
Chris Sanders πŸ”Ž 🧠
2 days
Investigation Scenario πŸ”Ž You discovered a suspicious PDF on a user’s workstation and found this sandbox report referencing it: What do you look for to investigate whether the system was infected and its extent? #InvestigationPath #DFIR #SOC
1
13
59
@chrissanders88
Chris Sanders πŸ”Ž 🧠
9 days
Investigation Scenario πŸ”Ž You receive an alert that a Linux system is experiencing consistently high CPU usage. Running crontab -l for the related user, you see the pictured entry... However, when you check again, the crontab entry is gone. The file listed in the cron job is not currently available at that URL. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
Tweet media one
1
4
26
@chrissanders88
Chris Sanders πŸ”Ž 🧠
14 days
One of my favorite maxims for anomaly detection in investigations comes from archaeology... One stone is a stone; two stones are a feature; three stones are a wall.
3
3
22
@chrissanders88
Chris Sanders πŸ”Ž 🧠
15 days
These malware analysis lessons are a great way to learn how the folks doing this work every day think through their analysis process and understand how malware behaves.
@NetworkDefense
Applied Network Defense
16 days
In our latest Analyst Skills Vault lesson, @ForensicITGuy breaks down how to analyze and decode the Meduza stealer malware's network communication traffic.
Tweet media one
0
1
13
@chrissanders88
Chris Sanders πŸ”Ž 🧠
16 days
@MWollenweber Bless your heart
1
0
1
@chrissanders88
Chris Sanders πŸ”Ž 🧠
16 days
@MWollenweber Who said they were unprivileged or that they didn't make any changes?
1
0
2
@chrissanders88
Chris Sanders πŸ”Ž 🧠
23 days
RT @RuralTechFund: Check out the awesome video put together for our project in Los Lunas, NM! "Thank you so much to the Rural Technology F…
0
2
0
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
This scenario was inspired by AgentTesla, for those trying for bonus points. That said, it's pretty hard to get there from a file name alone, and other malware strains use that filename, too.
0
0
2
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
Investigation Scenario πŸ”Ž While threat hunting, you’ve discovered a host receiving HTTPS traffic on port TCP/53. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
3
3
22
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
@mtk01330 Thank you πŸ’™
0
0
0
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
Nobody in Georgia knows what to do when it snows, so of course somebody is shooting off fireworks at 8:30 in the morning.
0
0
12
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
Not many better ways to ring in the New Year! One of these days I'm gonna talk them into letting me run the grill for a couple of hours. #WaffleHome
Tweet media one
1
0
10
@chrissanders88
Chris Sanders πŸ”Ž 🧠
1 month
@mtk01330 That's a big question! Any specific facet of cyber security, specifically?
1
0
1