Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Richard Bejtlich

@taosecurity@infosec.exchange
  • Open on infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight@infosec.exchange. My latest books are here #ad https://amzn.to/3B2AcMc

0 Followers
0 Following
14 Posts
Joined November 02, 2022
TaoSecurity:
https://www.taosecurity.com/index.html
Blog:
https://taosecurity.blogspot.com/
LinkedIn:
https://www.linkedin.com/in/richardbejtlich/
Amazon:
https://www.amazon.com/-/e/B001IR3KOW

Posts

Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 30, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Episode 20 of the Corelight podcast is live. This time, I'm the guest! Vince Stoffer interviews me about my newest book, NDR Essentials, which I wrote for Corelight. The book is free here, BTW: https://corelight.com/cp/ndr-essentials https://www.youtube.com/playlist?list=PLBKbF72bCp2UtefR6_GhrKATP3tVD7Vev https://open.spotify.com/show/2L2bkmbxaMxlz46xzhPNAH https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 20, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Every year on this day, I watch this brilliant music video and celebrate one of the greatest achievements of our civilization. https://youtu.be/BHIo6qwJarI?si=I8buXr-BscNOQlbn
0
0
0
1
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 19, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Mortal Kombat voice: “It has begun!” “Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.” https://huggingface.co/blog/security-incident-july-2026
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 17, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this. In April, the project released 8 advisories, with 6 powered by AI. In May, the count decreased sightly to 7. Today I took a look at the FreeBSD Security Advisory page to check the latest advisory count. June saw the most number of advisories ever published in project history: 25. See my latest blog for more: https://taosecurity.blogspot.com/2026/07/freebsd-released-most-security.html
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 16, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @gnyman@infosec.exchange
@gnyman@infosec.exchange fixed, thanks!
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 12, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @debian@framapiaf.org
@debian@framapiaf.org thanks as always for your work. 🙏
0
0
1
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 06, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
I wrote a blog post about my new book. The book is free BTW, no email required. Blog post is here: https://corelight.com/cp/ndr-essentials
0
1
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 04, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @jerry@infosec.exchange
@jerry@infosec.exchange what a dear! ❤️
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Jul 03, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Episode 18 of the Corelight podcast is live. I speak with Senior Sales Engineers Adam Donadeoto and Nico Roosenboom about their experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. We dive into the friction of defending a massive virtualized network against waves of red teamers. https://www.youtube.com/playlist?list=PLBKbF72bCp2UtefR6_GhrKATP3tVD7Vev https://open.spotify.com/show/2L2bkmbxaMxlz46xzhPNAH https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362
0
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Apr 21, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @dougburks@infosec.exchange
@dougburks @zeek 🫡
1
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Apr 20, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @dougburks@infosec.exchange
@dougburks @zeek integration next? 🙏
1
1
1
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Apr 06, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange

Do you see that crescent at the far right of the image? That’s US! The larger crescent in the middle is the moon, and the left is the Artemis II mission spacecraft.

5
0
1
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Mar 09, 2026
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @choomba@social.tchncs.de
@choomba@social.tchncs.de @b0rk@social.jvns.ca When a filter is tough to understand, you can dump the filter with -d and step through the compiled packet-matching code to see what it does. See https://taosecurity.blogspot.com/2004/09/understanding-tcpdumps-d-option-have.html and https://taosecurity.blogspot.com/2004/12/understanding-tcpdumps-d-option-part-2.html
1
0
0
0
Open post
taosecurity
Richard Bejtlich @taosecurity@infosec.exchange · Aug 19, 2025
Richard Bejtlich
@taosecurity@infosec.exchange

I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight. My latest books are here #ad https://amzn.to/3B2AcMc

infosec.exchange
Replying to @phrack@haunted.computer
@phrack@haunted.computer nice to see you are still around!
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:35:52 UTC