Library

Library

Personally built and tested: incident-response playbooks, first-aid guidance and reference material for limiting damage when it is already happening. A principle of medicine applies exactly to incident response — do no harm. Most of the damage in an incident is done by the response, not the intruder. These are written to help a CSIRT avoid the common errors.

Incident response playbooks

Procedures for investigation and response — identify, contain, eradicate, recover.

White papers and research

Written by me, from research and from the engagements behind it.

White paperMine Securing VoIP Approaches to VoIP security and the practices that keep the underlying infrastructure intact — written as MSc research. Available on request →
White paperMine Secure Unified Communication Threats to unified communications infrastructure, the defence strategies that answer them, and what each one costs a business. Co-authored with Gabriela. Available on request →
Research paperMine Effect of Security on Throughput of IEEE 802.11b/g Proposes Opportunistic Encryption — a framework that adapts the cipher to an acceptable signal-to-noise ratio rather than paying the same throughput cost everywhere. Available on request →
ProjectMine Search Machine, Since 1999 My own crawler and search engine, first written in 1999 for data mining, text search, media monitoring and analysis of large document collections. Available on request →

Field guides and frameworks

Methodology and technique, from live engagements rather than a slide pack.

FrameworkMine Penetration Testing Framework A pen tester's job is to demonstrate and document a flaw. This is the reconnaissance-to-report structure that keeps an engagement repeatable. Read → GuideMine NMAP Deep Dive Nmap finds the services and ports your servers expose. This walks the features most people never reach for. Read → Guide Mobile Security Testing Guide The OWASP manual for mobile application security testing and reverse engineering — the reference I test iOS and Android estates against. Read on the web ↗
GuideMine Avoid the WPA Wireless Attack The crack in Wi-Fi Protected Access, what it actually threatens in an enterprise network, and the configuration that closes it. Available on request →
GuideMine Blocking Tor Proxy Users Making a Linux server appear offline to Tor exit nodes only, by closing the connection with a TCP RST rather than a visible block page. Available on request →
GuideMine Nine Facts About Colocation Every part of the infrastructure carrying your customer interactions deserves scrutiny — including the colocation provider you inherited. Available on request →
GuideMine Exploitation: An IT Guy's Life in Hell How a system reacts under attack, which weak spots would actually be breached, and what data leaves a live system once they are. Available on request →

Tools

Built, run or hardened on engagements.

Threat intelligence and reports

What the criminal market is doing, and what the numbers say about the defence.

ReportMine Threat Intelligence Report Staying ahead of cyber criminals: turning collected data about a threat into structured, reliable intelligence that drives a decision. Read →
Report Hacker Business Models An inside look at how industrialised attackers operate. They have one goal — money — and they know the same rules about raising revenue and cutting cost as any business. Available on request →
ReportMine GDPR Will Require 28,000 DPOs European data protection rules would require 28,000 data protection officers appointed across Europe inside two years — a hiring problem before it was a compliance one. Read →
Report Cyberthreat Defence Report An organisation's own staff remain its largest security weakness, according to the CyberEdge Group survey of defenders. Available on request →

Reference and templates

Documents to adapt rather than read once.

Read the writing InfoSec tools