Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Chris Sanders 🔎 🧠

@chrissanders88@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security Analyst, Author, and Instructor, Ed.D.

Studying the intersection of security investigation doctrine, cognitive psychology, and education.

Founder of Applied Network Defense and Rural Tech Fund

Books:
🍯 Intrusion Detection Honeypots
🦈 Practical Packet Analysis
🌐 Applied Network Security Monitoring

Former: Mandiant, InGuardians, Dept of Defense, Roadside Fruit Vendor.

A question well stated is a problem half-solved. #InvestigationTheory

https://chrissanders.org/links/

1930 Followers
375 Following
29 Posts
Joined November 05, 2022
Blog:
https://chrissanders.org/
Training Courses:
http://networkdefense.co/courses/
Twitter:
https://twitter.com/chrissanders88
Books:
https://chrissanders.org/publications
More Links:
https://chrissanders.org/links/
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2w ago
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection. #DFIR #IDS #Honeypots
13
2
8
1
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 3mo ago
"Show your work." When I was in school, kids would get mad when teachers would ask them that. "What does it matter so long as I get the right answer?" Showing your work has always been the essential lesson, because eventually, someone will tell you that you’re wrong. If you can’t explain how you reached your conclusion, you can’t defend it. Your value isn’t just producing an answer... It’s being able to explain, defend, and adapt your reasoning. It's never been more valuable than now.
145
13
86
3
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
Call it what you like, but this is a rural tax from USPS. People in rural communities already have fewer local shopping options and rely more heavily on mail delivery. Making lightweight packages more expensive to send there seems antithetical to the idea of this public service.
52
9
35
1
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

I ask everyone who starts my Investigation Theory class, "What's a valuable trait or skill for an analyst to have?"

Many say "thinking outside the box"

And sometimes, unconventional solutions are exactly what’s needed.

But the pursuit of novelty can't be an excuse for ignorance of proven doctrine, either.

Sometimes we need folks thinking outside the box, but more often, we just need to understand the box better.

#DFIR #SOC #CyberSecurity

infosec.exchange

Infosec Exchange

10
0
7
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2w ago
Replying to
CISA’s report makes it clear that these techniques are valuable, especially when attackers use legitimate credentials and tools that make malicious activity harder to distinguish from normal behavior. If you want to actually implement these ideas, I wrote the book Intrusion Detection Honeypots specifically around this philosophy. I also have a hands-on course that walks through designing and deploying IDHs in real environments.
3
1
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2w ago
I’ve taken a surprising number of calls lately from people wanting to understand how human reasoning differs from machine inference. How do analysts reason through uncertainty? How do we form hypotheses? What makes us notice one piece of evidence and ignore another? Where does intuition come from? How are human judgment and machine inference fundamentally different?
1
0
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

A whole bunch of people DM'd me about meeting Cliff Stoll in Vegas and I love that I've done things in my life that have folks wanting to share that specific joy with me. 💙😂 #cuckoosegg

infosec.exchange
5
0
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
This may be a hot take, but a senior title should recognize someone who consistently applies broad experience, sound judgment, and nuanced perspective across a wide range of situations... not just someone who possesses a rare or in-demand technical skill at the time.
7
1
2
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

Investigation Scenario 🔎

A user’s RecentDocs LNK file points to C:\Users\Public\Libraries\update.iso, mounted shortly before rundll32.exe launched update.dll from the new drive letter. The ISO is now gone.

What do you look for to investigate whether an incident occurred?

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
Investigation Scenario 🔎 Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation. No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command? To go further, what would you look for to determine whether the alert represents the beginning of an ACR Stealer intrusion? #InvestigationPath #DFIR #SOC
3
1
4
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
In a recent study, those who actively planned, monitored, and critiqued their thinking (aka higher metacognitive skills) used LLMs more effectively and produced more creative work. Thinking about thinking has never mattered more.
3
1
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
Replying to
@deirdrebeth@mas.to No, it's new. UPS does a 1lb minimum, but USPS has previously done by-the-ounce pricing.
2
2
1
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

Investigation Scenario 🔎

You received an alert that one of your honeydocs was opened on a network other than your own.

What do you look for to investigate whether an attacker exfiltrated this file from your network?

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

1
0
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago

Investigation Scenario 🔎

While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location.

What do you look for to investigate whether an incident occurred?

Bonus Exercise: List several of the potential explanations for this behavior

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

1
0
1
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 5mo ago

RE: @dougburks@infosec.exchange

Doug built ANOTHER useful thing! I had a chance to play around with OhMyPCAP pre-release... super handy and worth having in your toolbox!

infosec.exchange
4
0
3
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 2mo ago
Investigation Scenario 🔎 A Windows 11 workstation’s Microsoft-Windows-TaskScheduler/Operational log contains Event ID 106, indicating a new scheduled task named "OneDrive Update Service" was registered at 5:45 PM local time. The user insists they were away from the computer when this happened. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
1
2
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 3mo ago

You always want to take the smallest slice of data necessary to answer an investigative question you're asking. It forces you to be focused and specific, while also limiting data processing time and resource utilization on your tools. I preach this frequently to my Investigation Theory students.

1
1
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 7mo ago
Boosted by @ferrix@mastodon.online
"...the propensity for prosocial behavior may be reduced in states of cognitive fatigue resulting from the extended exertion of self-control." similar to "sleep-like activity" Prolonged cognitive fatigue ➡️ frontal cortex changes ➡️ more aggressive and uncooperative
2
0
5
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 5mo ago

When you hear the word "identity" in cybersecurity, what does that mean to you? How do you define it?

1
0
2
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 3mo ago
Replying to
This is also our 150th (!) investigation scenario! I'll pick a favorite response at the end of the week and give you a free class at https://networkdefense.io
networkdefense.io
0
0
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 3mo ago
Replying to
If you're not familiar with these files or Linux persistence, this scenario is a good opportunity to practice your research skills. Good analysts take novelty cues like this and leverage them to build their tradecraft knowledge.
0
1
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

Investigation Scenario 🔎

While investigating a potentially compromised host, you've discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no knowledge of ever using this application.

What do you look for to investigate whether the tool was used for malicious purposes?

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 1mo ago

Investigation Scenario 🔎

While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 system.

The user claims they only connected a USB-C docking station.

What do you look for to investigate whether an incident occurred? Extra credit for focusing on the distinct order of operations you would take.

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 3w ago

Investigation Scenario 🔎

A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds, but the referenced file never appears in the MFT.

What do you look for next to determine what the user actually opened and whether malicious execution followed?

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

0
0
0
0
Open post
Chris Sanders 🔎 🧠 @chrissanders88@infosec.exchange
· 4w ago

Investigation Scenario 🔎

Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could investigate. You only have Windows Event Logs (default config) and network sensor data. What do you look for to determine whether an incident occurred?

#InvestigationPath #DFIR #SOC

infosec.exchange

Infosec Exchange

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:11:56 UTC