Library
Library
Personally built and tested: incident-response playbooks, first-aid guidance and reference material for limiting damage when it is already happening. A principle of medicine applies exactly to incident response — do no harm. Most of the damage in an incident is done by the response, not the intruder. These are written to help a CSIRT avoid the common errors.
Incident response playbooks
Procedures for investigation and response — identify, contain, eradicate, recover.
Phishing Incident Response
The procedures for security event investigation and response — written guidance for identifying, containing, eradicating and recovering from a phishing compromise.
Read on the web ↗
NotPetya Ransomware Outbreak
On 27 June several organisations across Europe reported ransomware in their systems. Written as it unfolded, from crowd-sourced intelligence rather than after the fact.
Read on the web ↗
Crowd-Sourced Intelligence: WannaCry
WannaCry stopped? No — the kill switch only slowed it. A live intelligence document assembled from the response community while the outbreak was still running.
Available on request →
Defend Against DDoS Attacks
DDoS makes the headlines, but architecting the DNS layer correctly removes most of the impact before the traffic ever reaches you.
Read →
Modern Disaster Recovery Toolkit
No more excuses. Building a recovery toolkit, and monitoring the strategy so it alerts you to the moves, adds and changes that quietly break the plan.
Available on request →
White papers and research
Written by me, from research and from the engagements behind it.
Securing VoIP
Approaches to VoIP security and the practices that keep the underlying infrastructure intact — written as MSc research.
Available on request →
Secure Unified Communication
Threats to unified communications infrastructure, the defence strategies that answer them, and what each one costs a business. Co-authored with Gabriela.
Available on request →
Effect of Security on Throughput of IEEE 802.11b/g
Proposes Opportunistic Encryption — a framework that adapts the cipher to an acceptable signal-to-noise ratio rather than paying the same throughput cost everywhere.
Available on request →
Search Machine, Since 1999
My own crawler and search engine, first written in 1999 for data mining, text search, media monitoring and analysis of large document collections.
Available on request →
Field guides and frameworks
Methodology and technique, from live engagements rather than a slide pack.
Penetration Testing Framework
A pen tester's job is to demonstrate and document a flaw. This is the reconnaissance-to-report structure that keeps an engagement repeatable.
Read →
NMAP Deep Dive
Nmap finds the services and ports your servers expose. This walks the features most people never reach for.
Read →
Mobile Security Testing Guide
The OWASP manual for mobile application security testing and reverse engineering — the reference I test iOS and Android estates against.
Read on the web ↗
Avoid the WPA Wireless Attack
The crack in Wi-Fi Protected Access, what it actually threatens in an enterprise network, and the configuration that closes it.
Available on request →
Blocking Tor Proxy Users
Making a Linux server appear offline to Tor exit nodes only, by closing the connection with a TCP RST rather than a visible block page.
Available on request →
Nine Facts About Colocation
Every part of the infrastructure carrying your customer interactions deserves scrutiny — including the colocation provider you inherited.
Available on request →
Exploitation: An IT Guy's Life in Hell
How a system reacts under attack, which weak spots would actually be breached, and what data leaves a live system once they are.
Available on request →
Tools
Built, run or hardened on engagements.
High-Performance DoS Analyzer
DoS and DDoS load analysis over NetFlow, IPFIX, sFlow, SnabbSwitch, Netmap, PF_RING and PCAP — detecting hosts sending or receiving abnormal packet volume.
Read →
ssh-audit: SSH Server Auditing
Banner grab, SSH1 and zlib detection, and a full read of the key exchange, encryption and message authentication a server will actually negotiate.
Read →
USBdeath: USB Anti-Forensics
Writes udev rules for known USB devices, then acts on the insertion of an unknown one or the removal of a specific one.
Available on request →
Threat intelligence and reports
What the criminal market is doing, and what the numbers say about the defence.
Threat Intelligence Report
Staying ahead of cyber criminals: turning collected data about a threat into structured, reliable intelligence that drives a decision.
Read →
Hacker Business Models
An inside look at how industrialised attackers operate. They have one goal — money — and they know the same rules about raising revenue and cutting cost as any business.
Available on request →
GDPR Will Require 28,000 DPOs
European data protection rules would require 28,000 data protection officers appointed across Europe inside two years — a hiring problem before it was a compliance one.
Read →
Cyberthreat Defence Report
An organisation's own staff remain its largest security weakness, according to the CyberEdge Group survey of defenders.
Available on request →
Reference and templates
Documents to adapt rather than read once.
Information Sensitivity Policy
Helps staff decide which technical controls apply to which information — the classification decision that every other control depends on.
Available on request →
CCISO Table of Contents
The full syllabus behind EC-Council's Certified CISO programme — useful as a gap checklist whether or not you sit the exam.
Read →
T1
Top 100 Hacking Books
A hundred books for anyone working in ethical hacking, beginner or professional, ranked on published reviews rather than my own preference.
Read →