Posts about security

Networking tips for your first conference


Tags: travel, career, how-to, security, research

I wrote this list of tips for networking just after I visited my first conference, where networking was supereasy! And it was FUN! Although Troopers 2017 was an industry conference, the tips should work fine for academic conferences too.

I talked to so many interesting people, people working in infosec from all over the globe. I even managed to help some of them, by answering questions on social media, introducing people to each other, and pointing people to good self-education resources on the internet. I love to help people, so that made the networking activity feel very natural for me. It was not like the picture I had in my head at all (people in suits loudly talking about themselves while scattering business cards at random). I also loved to exchange horror stories about employers or infosec-gone-wrong. And the most fun thing is to form a spontaneous group of conference-friends and explore the local cuisine.

Read more...

Computer security resources for self-study and career planning


Tags: security

This is a list of self-study resources for people that want to get into the computer security field. I started this list in december 2015, just before I started my job as a security specialist at the National Cyber Security Centre of the Netherlands. It contains resources for learning new techniques and tools, self-study, career planning and personal development. All of these were useful to me personally, and every link is hand-picked. ;)

Read more...

My experiences at infosec conference TROOPERS 2017


Tags: security, travel

Last month, I visited TROOPERS17, a conference in Heidelberg, Germany. It was the first infosec conference I've attended, so I didn't really know what to expect. The website showed photos of geeky people in hoodies, a soldering table, lots of club mate and weird LED badges. I figured I could fit right in, and when I saw the training program I was even more motivated to register.

In the two days before the conference, I followed a training about network forensics. Earlier this week I wrote about the Rinse and Repeat technique I learned there, which can help you find the interesting network activity in a large PCAP-file.

Read more...

Some thoughts on responsible vulnerability disclosure


Tags: security

It's hard for system owners to keep their systems secure. Servers and devices are scanned, defaced, compromised by the minute, by newbies playing around with github scripts, nation state actors and everything in between. Lucky for us, a growing group of ethical hackers spends time hunting and reporting vulnerabilities.

Read more...

Rinse and Repeat: threat hunting with CapLoader and Wireshark


Tags: security

When I was visiting TROOPERS17 in Heidelberg, Germany, I had the chance to follow a 2-day training in Network Forensics by Erik Hjelmvik. I'm glad I did! In this post I want to describe a technique I learned there. This technique is a nice way to investigate captured network traffic to find suspicious or malicious traffic. Although I dislike the term 'threat hunting', this is actually a neat and fast way to hunt for the weird and interesting stuff in a large PCAP-file!

The workflow I want to describe could be called "Rinse and repeat". I like it because it is elegant: simple and flexible, but powerful if used right.

Read more...

Getting started with malware analysis for absolute beginners


Tags: security

A few months ago I did some basic malware analysis as part of an incident responder training. As I was completely new to the field of malware analysis, I learned a lot of new things. This primer is my way of sharing my experiences as a beginner in the field. In this write-up, I want to describe some of the basics and point enthusiastic beginners like myself in the direction of more self-education resources.

I use the following broad, pragmatic definition of malware: malware is basically anything malicious that potentially has a negative impact on a system.

Read more...