Sign in

Chris Sanders 🔎 🧠

@chrissanders88.bsky.social
794 followers 2 following 412 posts

Digital Forensic Analyst, Researcher, Author Ed.D. Founder Applied Network Defense and Rural Tech Fund Former Mandiant, InGuardians, DoD Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM

PostsRepliesMedia
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 9h
The more evidence sources you understand, the larger your investigative playing field becomes. As you understand how to think, you should also be expanding the field you operate in. #SOC #DFIR #CyberSecurity
030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 30/09/2026
Investigation Scenario 🔎 Windows Defender Event ID 5007 shows DisableRealtimeMonitoring changed from 0 to 1, yet MsMpEng.exe appears to still be running. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
210
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
I was recently asked to advise on a product. The project lead showed me how his tool could take an alert, find the relevant data, and make investigative decisions based on what it found.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 23/09/2026
Investigation Scenario 🔎 Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred. What do you examine next to determine who added the credential and whether it was used? #InvestigationPath #DFIR #SOC
010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026
I’ve taken a surprising number of calls lately from people wanting to understand how human reasoning differs from machine inference.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). #DFIR #IDS #Honeypots
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/09/2026
Investigation Scenario 🔎 A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds, but the referenced file never appears in the MFT.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/09/2026
Investigation Scenario 🔎 Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could investigate. You only have Windows Event Logs (default config) and network sensor data. What do you look for to determine whether an incident occurred?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/09/2026
Investigation Scenario 🔎 A user’s RecentDocs LNK file points to C:\Users\Public\Libraries\update.iso, mounted shortly before rundll32.exe launched update.dll from the new drive letter. The ISO is now gone. What do you look for to investigate whether an incident occurred?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/09/2026
I ask everyone who starts my Investigation Theory class, "What's a valuable trait or skill for an analyst to have?" Many say "thinking outside the box" And sometimes, unconventional solutions are exactly what’s needed.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/08/2026
Investigation Scenario 🔎 While investigating a potentially compromised host, you've discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no knowledge of ever using this application. What do you look for to investigate whether the tool was used for malicious purposes?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/08/2026
Investigation Scenario 🔎 While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 system. The user claims they only connected a USB-C docking station.
Registry details show a USB mass storage device connected to a Windows 11 system, including installation date and device type.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026
Investigation Scenario 🔎 You received an alert that one of your honeydocs was opened on a network other than your own. What do you look for to investigate whether an attacker exfiltrated this file from your network? #InvestigationPath #DFIR #SOC
111
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026
A whole bunch of people DM'd me about meeting Cliff Stoll in Vegas and I love that I've done things in my life that have folks wanting to share that specific joy with me. 💙😂 #cuckoosegg
030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/07/2026
Investigation Scenario 🔎 While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 23/07/2026
This may be a hot take, but a senior title should recognize someone who consistently applies broad experience, sound judgment, and nuanced perspective across a wide range of situations... not just someone who possesses a rare or in-demand technical skill at the time.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 21/07/2026
Investigation Scenario 🔎 Alert: Microsoft Defender for Endpoint: Behavior:Win32/SuspClickFix.F detected on a Windows 11 workstation. No additional context is provided. What artifacts would you examine first to determine whether the user executed the ClickFix command?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/07/2026
Call it what you like, but this is a rural tax from USPS. People in rural communities already have fewer local shopping options and rely more heavily on mail delivery. Making lightweight packages more expensive to send there seems antithetical to the idea of this public service.
New USPS rates increase shipping costs for packages under 1 pound to rural areas, affecting delivery logistics for those communities.
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 15/07/2026
In a recent study, those who actively planned, monitored, and critiqued their thinking (aka higher metacognitive skills) used LLMs more effectively and produced more creative work. Thinking about thinking has never mattered more.
Research article details on how generative AI affects workplace creativity, highlighting metacognitive strategies and employee performance.
131
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 14/07/2026
Investigation Scenario 🔎 A Windows 11 workstation’s Microsoft-Windows-TaskScheduler/Operational log contains Event ID 106, indicating a new scheduled task named "OneDrive Update Service" was registered at 5:45 PM local time. The user insists they were away from the computer when this happened.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 10/07/2026
You always want to take the smallest slice of data necessary to answer an investigative question you're asking. It forces you to be focused and specific, while also limiting data processing time and resource utilization on your tools. I preach this frequently to my Investigation Theory students.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/07/2026
"Show your work." When I was in school, kids would get mad when teachers would ask them that. "What does it matter so long as I get the right answer?"
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 07/07/2026
Investigation Scenario 🔎 You’ve found ~/.config/systemd/user/dbus-update.service enabled for a user account on an Ubuntu system. The service executes ~/.local/bin/dbus-update, an ELF binary that isn’t owned by any installed package.
130
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/07/2026
I was on vacation, so no Investigation Scenario this week. Spend your time investigating some lemonade and hot dogs!
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/06/2026
One thing I wish I could relay more to learners and teachers alike... The better you know a subject, the harder it is to imagine what it is like for someone else not to know it. That's a curse of knowledge. It's hard to remember what it was like when you didn't know that thing.
120
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 23/06/2026
Investigation Scenario 🔎 An LLM has reviewed domain authentication logs and suggested that an account is likely compromised, based on several successful authentication clusters that occurred frequently over the past week. What do you look for to investigate whether an incident occurred?
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 19/06/2026
With all the recent M&A activity and more certainly to come, I keep arriving back at the same question... are people going to be safer?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/06/2026
Investigation Scenario 🔎 While hunting, you identify an outlier host with a Windows Prefetch file named RUNDLL32.EXE-3F2A9B1C[.]pf The file shows a run count significantly higher than the baseline observed across the environment, with multiple recorded execution timestamps occurring overnight.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/06/2026
I use LLMs for a variety of tasks every day and frequently benchmark domain-specific tasks across different models for my research. So, where am I on LLM use for security analysis and investigation work? In short summary:
150
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/06/2026
Investigation Scenario 🔎 You've discovered a Sysmon log (EID 13) showing reg.exe writing a value into the HKCU\Software\firm\soft\Name registry key. What do you look for to investigate whether an incident occurred and the extent of its impact? #InvestigationPath #DFIR #SOC
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/06/2026
Good analysts understand the importance of data perspective... changing their altitude! They zoom in to examine the elements of individual events or zoom out to consider a series of related events.
Diagrams of planes represent different analytical approaches: discrete analysis focuses on specific events, while holistic analysis considers the overall context.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/06/2026
"...repeated exposure to information has a more profound influence on people's beliefs in settings where people actively choose which information they are exposed to." pubmed.ncbi.nlm.nih.gov/41505278/
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/06/2026
Investigation Scenario 🔎 You notice Event ID 7040 in the System log. The startup type of the Remote Registry service changed from Disabled to Manual for 14 minutes, then back to Disabled. No corresponding service-install events exist.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 27/05/2026
Most highly effective analysts don't just read logs; they mentally map out the network and visualize the attack as physical movement. They conceptualize functional boundaries and the attack surface available at any given foothold (even if they don't realize they're doing it).
200
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 26/05/2026
Investigation Scenario 🔎 An employee's Android phone recently made multiple connections to an IP address associated with prior malicious activity. The /data/system/packages.xml file shows a recently installed APK named com[.]secure.update, signed with an unknown cert.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/05/2026
I'll be speaking about our work @RuralTechFund. Looking forward to seeing folks there.
A virtual event poster for RejectionCon 26 features a title, a colorful background, and a character alongside a speaker's photo. Chris Sanders talk title is That Kid, and Their Person.
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/05/2026
Abstraction simplifies complex data so we can process it quickly, but it also hides data and creates blind spots. We do this with domain names, timestamps, and all sorts of other fields. If your tool automatically drops certain fields or trims logs, you might be missing the full story
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20/05/2026
Good playbooks are not just mindless checklists; they are built on inductive reasoning. We observe patterns in specific attacks and generalize them to predict the right investigative questions for future incidents.
221
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 19/05/2026
Investigation Scenario 🔎 A host on your network downloaded a file with this SHA256 hash: 9297af5f66486d11540f15b44d4b6beec6ff89dbc4dcdee898db9a7daaa76085 What do you look for to investigate whether the malware infected the host? You can only make two queries -- make them count.
200
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 14/05/2026
Many of the same people who don't understand how analysts think are trying to tell AI how to do it and sell you the results. You shouldn't trust any of them.
130
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 12/05/2026
Investigation Scenario 🔎 You've discovered a user workstation with the Chrome Remote Desktop plugin installed. There's no business reason for the user to have this plugin, and they don't recall installing it.
121
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 08/05/2026
Launching attacks against Canvas at the most critical point of the school year harms students and adds even more strain to teachers already carrying an extraordinary burden for salaries that are far too low for the work they do.
022
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/05/2026
Investigation Scenario 🔎 While creating new user accounts in Active Directory, you find that several legitimate user accounts with no apparent connection are part of an undocumented group named "test".
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/04/2026
Investigation Scenario 🔎 A high-level company exec received an email that someone logged into their social media account from a country they were not in. The exec noted that they use the same password in several places.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 27/04/2026
Is there any great way to tell someone, "Hey, it's clear this thing you wrote is AI, and I think when you write in your own voice, it's so much better"
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 21/04/2026
Investigation Scenario 🔎 You believe a Linux server was used as a jump box to pivot into another network segment, but the network traffic would not have crossed a sensor boundary for logging. What evidence do you look for to prove the belief? #InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 17/04/2026
When you hear the word "identity" in cybersecurity, what does that mean to you? How do you define it?
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 14/04/2026
Investigation Scenario 🔎 You run IT for a public high school. A teacher observed a student using AI to generate ideas for accessing the school grading system and reported it. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 31/03/2026
Investigation Scenario 🔎 A user reports their hard drive is full, but they don't know why. While investigating, you find a series of large, password-protected RAR files that the user knows nothing about.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 30/03/2026
This article is about intro psych courses, but it highlights a common problem across many fields at universities, including tech-related. Introductory courses are designed to prepare students for further study in a field, yet in reality, may be their only exposure to it.
The article discusses challenges in teaching introductory psychology courses and the need for effective reform to enhance student understanding.
110