Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hWe can’t sacrifice investigative quality just to say we’ve automated more of the investigation. The stakes are too high. 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hAs LLMs increasingly find their way into security products, I think this distinction becomes even more important. I see that IT mindset driving some security products, and that can lead folks down the wrong path. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hWe absolutely should automate the parts of investigative work that lend themselves to it. But, automation isn’t the goal. The goal is to make good decisions and not miss important things. Automation should serve those goals, not compete with them. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hSecurity investigations are different. They involve ambiguity, incomplete evidence, unpredictable failure modes, changing context, and frequent judgment calls. The number of ways an investigation can go sideways is much harder to constrain. That doesn’t mean we shouldn’t automate. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hIn IT, automation often drives the work. Many tasks are deterministic, and we can anticipate their failure modes, test them, and engineer around them. If you can reliably automate a process, that’s usually a win. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20hAn IT mindset offers a lot of benefits to someone entering security. The mental models, troubleshooting habits, and systematic thinking developed in IT overlap meaningfully with the skills needed for security investigations. But there are differences, too. One is how we think about automation. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 07/10/2026The production VMDK still exists in its normal datastore, but it no longer exists in the referenced path. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 07/10/2026Investigation Scenario 🔎 While reviewing the ESXi hostd.log, an analyst spots a network file connection referencing a known VM disk, but at an unexpected path different from where it typically runs from: /vmfs/volumes/BackupDS/temp/Finance01.vmdk 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026I suppose that all may seem irrelevant to digital forensics, but ultimately, we're in this business for the people, the relationships we form, and the others we help protect. 020
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026There’s something magical about that moment. You’re taking two separate memories of the same event and turning them into a shared story... co-writing a narrative of your past, together. 120
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026What the other person was wearing. How nervous or awkward you were. What you ate. The dumb jokes you made. Your first impressions of each other. The little details one of you remembers that the other had already forgotten. 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026Do you ever think about when a friendship or relationship really begins? Maybe it’s when you first meet, or the first time you realize you genuinely enjoy being around each other. But I think we often miss something... the first time you reminisce together about how you met or your early moments. 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/10/2026In your message, let me know how much overall forensic experience you have, and how much work you've done in browser forensics specifically (and which browsers). 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/10/2026We've got a new course releasing soon -- Browser Forensics for Security Analysts. I'm looking for a couple of reviewers at different experience levels who'd like to go through the course and can do so relatively quickly! Send me a message if you're interested. 210
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/10/2026The more evidence sources you understand, the larger your investigative playing field becomes. As you understand how to think, you should also be expanding the field you operate in. #SOC #DFIR #CyberSecurity 030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 30/09/2026Investigation Scenario 🔎 Windows Defender Event ID 5007 shows DisableRealtimeMonitoring changed from 0 to 1, yet MsMpEng.exe appears to still be running. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC 210
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026Tools can make you a better analyst, but you have to be metacognitively aware enough to know where they fit in, where they have limits, and where it all might lead you astray. #DFIR #SOC #CyberSecurity 010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026It turns out that when you don't have the ability to evaluate investigative actions effectively, you can't build products or train LLMs effectively for that task either. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026So, I gave the same alert to the product lead and asked him to list the investigative questions he would pursue. The list he gave me wasn't very good either. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026I gave the tool a Suricata alert to work through. It wasted a lot of effort, sent the analyst down rabbit holes, and failed to resolve the questions that mattered most. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026I was recently asked to advise on a product. The project lead showed me how his tool could take an alert, find the relevant data, and make investigative decisions based on what it found. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 23/09/2026Investigation Scenario 🔎 Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred. What do you examine next to determine who added the credential and whether it was used? #InvestigationPath #DFIR #SOC 010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026Among many who embrace it, that's leading to greater metacognitive awareness... people becoming more conscious of how they reason, not just what conclusions they reach. #DFIR #AI #LLM #Metacognition 020
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026The more we try to understand what LLMs can and can’t do effectively, the more we’re forced to examine the cognitive processes we’ve traditionally taken for granted in ourselves. 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026How do analysts reason through uncertainty? How do we form hypotheses? What makes us notice one piece of evidence and ignore another? Where does intuition come from? How are human judgment and machine inference fundamentally different? 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026I’ve taken a surprising number of calls lately from people wanting to understand how human reasoning differs from machine inference. 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026And here's the hands-on course: www.networkdefense.co/courses/hon...networkdefense.coBuilding Intrusion Detection HoneypotsBuilding Intrusion Detection Honeypots will teach you how to build, deploy, and monitor honeypots designed to catch intruders on your network. 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026Here's the CISA Report: www.cisa.gov/resources-t... Here's my Intrusion Detection Honeypots book: www.amazon.com/dp/17351883...amazon.comIntrusion Detection Honeypots: Detection through DeceptionThe foundational guide for using deception against computer network adversaries. When an attacker breaks into your network, you have a home-field advantage. But how do you use it? Intrusion Detection Honeypots is the foundational guide to building, deploying, and monitoring honeypots -- secu... 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026If you want to actually implement these ideas, I wrote the book Intrusion Detection Honeypots specifically around this philosophy. I also have a hands-on course that walks through designing and deploying IDHs in real environments. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026CISA’s report makes it clear that these techniques are valuable, especially when attackers use legitimate credentials and tools that make malicious activity harder to distinguish from normal behavior. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026The idea is simple: put something in your environment that nobody should touch, make it interesting to an attacker, and pay very close attention when somebody touches it. If you can control what an attacker sees and thinks, you can control what they do and find them. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026They’re low effort. They require very little tuning. And because legitimate users have no reason to interact with them, they can produce incredibly high-confidence alerts with very few false positives. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). #DFIR #IDS #Honeypots 110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/09/2026What do you look for next to determine what the user actually opened and whether malicious execution followed? #InvestigationPath #DFIR #SOC 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/09/2026Investigation Scenario 🔎 A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds, but the referenced file never appears in the MFT. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/09/2026Investigation Scenario 🔎 Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could investigate. You only have Windows Event Logs (default config) and network sensor data. What do you look for to determine whether an incident occurred? 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/09/2026Investigation Scenario 🔎 A user’s RecentDocs LNK file points to C:\Users\Public\Libraries\update.iso, mounted shortly before rundll32.exe launched update.dll from the new drive letter. The ISO is now gone. What do you look for to investigate whether an incident occurred? 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/09/2026But the pursuit of novelty can't be an excuse for ignorance of proven doctrine, either. Sometimes we need folks thinking outside the box, but more often, we just need to understand the box better. #DFIR #SOC #CyberSecurity 011
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/09/2026I ask everyone who starts my Investigation Theory class, "What's a valuable trait or skill for an analyst to have?" Many say "thinking outside the box" And sometimes, unconventional solutions are exactly what’s needed. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/08/2026Investigation Scenario 🔎 While investigating a potentially compromised host, you've discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no knowledge of ever using this application. What do you look for to investigate whether the tool was used for malicious purposes? 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/08/2026What do you look for to investigate whether an incident occurred? Extra credit for focusing on the distinct order of operations you would take. #InvestigationPath #DFIR #SOC 000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/08/2026Investigation Scenario 🔎 While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 system. The user claims they only connected a USB-C docking station. 100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026Investigation Scenario 🔎 You received an alert that one of your honeydocs was opened on a network other than your own. What do you look for to investigate whether an attacker exfiltrated this file from your network? #InvestigationPath #DFIR #SOC 111
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026A whole bunch of people DM'd me about meeting Cliff Stoll in Vegas and I love that I've done things in my life that have folks wanting to share that specific joy with me. 💙😂 #cuckoosegg 030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/07/2026What do you look for to investigate whether an incident occurred? Bonus Exercise: List several of the potential explanations for this behavior #InvestigationPath #DFIR #SOC 010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/07/2026Investigation Scenario 🔎 While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location. 110