BSides Las Vegas, 2016

I absolutely love giving presentations! I love to run my mouth, so being able to do so in front of like-minded individuals is a passion of mine. I’ve started to lose track of the various presentations I’ve given, so I made this page to catalogue my work and provide resources should anyone be interested in reviewing the content.

If you are a CISO, I have a few presentations on the SANS CISO Network’s OnDemand platform. You can learn more about joining the SANS CISO Network at https://www.sans.org/mlp/ciso-network/.


Table of Contents

Featured

PikaBot Malware Analysis: Debugging in Visual Studio – John Hammond’s YouTube channel [2024.02]

Recording here: https://www.youtube.com/watch?v=k2rH0ISuMwE — video embedded below

Hands-on Ransomware: Exploring Cybercrime – John Hammond’s YouTube channel [2023.05]

Recording here: https://www.youtube.com/watch?v=9zEXov_L0os — video embedded below

Detecting & Hunting Ransomware Operator Tools: It Is Easier Than You Think! – Community Night SANS Secure Australia 2023 [2023.03]

View live stream details and recording

Stay Ahead of Ransomware LIVEstream Series – Ep. 1: The Top 5 Misconceptions About Ransomware [2023.03]

View live stream details and recording

The Truth about Ransomware: Its not Complicated! [2023.01]

View Webcast details and recording

Learning to Combat Ransomware: An Overview of the NEW SANS FOR528 Course

View Webcast details and recording

Monti Ransomware: Is It a Doppelganger or a Pivot? — LinkedIn Live [2022.09]

View Webcast details and recording

Have Fun with It!: Tracking Ransomware Operator Lateral Movement and Recovering Deleted Files the Easy Way! — ResponderCon [2022.09]

View Webcast details and slides

Keynotes

Much Ado About Ransomware — US Secret Service’s National Computer Forensics Institute Ransomware Training Week [2021.10.11]

View presentation PDF

SANS Presentations

Healthcare Ransomware Discussion — SANS 2nd Annual Healthcare Forum [2023.10]

View Webcast details and recording

Security Isn’t Just a Job, It’s a Lifestyle: Tips for Ransomware Prevention — SANS Security Awareness Livestream [2022.10]

View Webcast details and recording

SANS Institute – Anatomy of a Ransomware Operation — On-demand Webinar [2022.10]

View Webcast details, recording

Ransomware and Healthcare. Ew. — SANS Healthcare Forum 2022: Vulnerabilities and Mitigation Techniques [2022.09]

View Webcast details and recording

Threats & Challenges 2021: What Cyber Defenders Need to Know – and Do — SANS Blue Team Summit 2021 [2021.09]

View Webcast details and recording

Ransomware, Security Awareness, and YOU! — SANS Security Awareness Summit 2021 [2021.08]

View Webcast details and recording

SANS Threat Analysis Rundown – Ransomware with guest speaker Ryan Chapman [2021.06.30]

View Webcast details and recording

Executives and Ransomware: Stop, Collaborate, and Listen! – SANS Webcast [2021.06.24]

View Webcast details and recording

Ransomware – Do You Pay It Or Not? – Experts debate the costs ethics around paying ransomware – SANS Webcast [2021.06.03]

View Webcast details and recording

Ransomware – Do You Pay It Or Not? – Experts debate the costs and ethics surrounding ransomware payments – SANS Webcast [2021.06.03]

View Webcast details and recording

Avoiding or Minimizing Ransomware Impact to the Bottom Line: A Panel Discussion – SANS Webcast [2021.05.27]

View Webcast details and recording

Ransomware Defense 101: A Simple Action Plan – SANS Healthcare Lightning Summit 2021 [2021.05.19]

View Webcast details and recording

Oh You Silly Framework!: An Intro to Analyzing .NET Malware – SANS Sydney 2020 @Mic Webcast [2020.11.04]

View Webcast details and recording

LOCKED OUT! Detecting, Preventing, & Reacting to Human Operated Ransomware – SANS Webcast [2020.10]

View Webcast description and details

Hunting Human-Operated Ransomware Operators – SANS Threat Hunting & Incident Response Summit 2020 [2020.09.11]

View Webcast details and recording

CactusCon & BSides Talks

Implementing a Kick-Butt Training Program: Blue Team GO! – BSides San Francisco & CactusCon 2019

View talk details and recording

Operationalizing Cyber Threat Intelligence (CTI): Pivoting & Hunting – CactusCon, 2018

No recording available

Exposing the Neutrino EK: All the Naughty Bits – BSides Las Vegas 2016

View talk details and recording

TAPIOCA: How to Automate Yourself Out of a Job – BSides Las Vegas 2015

View talk details and recording

Misc Presentations

Black Hat Research Preview – Linux Threats: A Black Hat 2022 Hot Topic? — LinkedIn Live [2022.08]

View Webcast details and recording

Protecting Your Workforce from Business Email Compromise – BlackBerry Webinar [2020.10.27]

View Webcast details and recording

Incident Response in Your Newly Expanded Workforce – Nth Generation Symposium 2020

No recording available

Threat Hunting in 2020: Focal Points for Success – SINC Virtual Roundtable New York/New Jersey

View Webcast details and recording

IT Security Outlook 2020: What to Expect in the Year Ahead – eSecurity Planet 2020

View Webcast details and recording

Threat Intelligence – Buzzword or Buzz-Worthy? – Cisco Threats: The Good, the Bad and the Ugly 2018

View Webcast details and recording

JavaScript Deobfuscation

MalWerewolf: JS/Shellcode Deobfuscation

View YouTube recordings (part 1 & 2)

Splunk Talks

PowerShell Power Hell: Hunting for Malicious PowerShell with Splunk – Splunk.Conf 2016

View talk recording

Security Operations Use Cases: ‘Cause Bears, Pandas, and Sandworms – Splunk.Conf 2015

View talk recording

Security Operations Use Cases: ‘Cause Bears, Pandas, and Sandworms – Splunk Live! Santa Clara 2014

Same as Splunk .Conf 2015 preso above

Security Operations: Hunting Wabbits, Possum, and APT – Splunk Live! Scottsdale 2014

View talk slides

Security Operations Center Use Cases – Splunk Live! Phoenix 2013

My first InfoSec talk!! Alas, no recording available.


Cyber Forensics Workshop

This is a 6-part workshop that I presented to students from Cal State University Fullerton (CSUF) back in 2014. While the version of WireShark we use is quite old, the content is still completely viable here in 2021-2022.

View workshop recordings from YouTube (all 6 parts!)