Sign in

Chris Sanders 🔎 🧠

@chrissanders88.bsky.social
796 followers 2 following 426 posts

Digital Forensic Analyst, Researcher, Author Ed.D. Founder Applied Network Defense and Rural Tech Fund Former Mandiant, InGuardians, DoD Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM

PostsRepliesMedia
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
We can’t sacrifice investigative quality just to say we’ve automated more of the investigation. The stakes are too high.
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
As LLMs increasingly find their way into security products, I think this distinction becomes even more important. I see that IT mindset driving some security products, and that can lead folks down the wrong path.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
We absolutely should automate the parts of investigative work that lend themselves to it. But, automation isn’t the goal. The goal is to make good decisions and not miss important things. Automation should serve those goals, not compete with them.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
Security investigations are different. They involve ambiguity, incomplete evidence, unpredictable failure modes, changing context, and frequent judgment calls. The number of ways an investigation can go sideways is much harder to constrain. That doesn’t mean we shouldn’t automate.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
In IT, automation often drives the work. Many tasks are deterministic, and we can anticipate their failure modes, test them, and engineer around them. If you can reliably automate a process, that’s usually a win.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 20h
An IT mindset offers a lot of benefits to someone entering security. The mental models, troubleshooting habits, and systematic thinking developed in IT overlap meaningfully with the skills needed for security investigations. But there are differences, too. One is how we think about automation.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 07/10/2026
The production VMDK still exists in its normal datastore, but it no longer exists in the referenced path. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 07/10/2026
Investigation Scenario 🔎 While reviewing the ESXi hostd.log, an analyst spots a network file connection referencing a known VM disk, but at an unexpected path different from where it typically runs from: /vmfs/volumes/BackupDS/temp/Finance01.vmdk
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026
I suppose that all may seem irrelevant to digital forensics, but ultimately, we're in this business for the people, the relationships we form, and the others we help protect.
020
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026
There’s something magical about that moment. You’re taking two separate memories of the same event and turning them into a shared story... co-writing a narrative of your past, together.
120
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026
What the other person was wearing. How nervous or awkward you were. What you ate. The dumb jokes you made. Your first impressions of each other. The little details one of you remembers that the other had already forgotten.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 06/10/2026
Do you ever think about when a friendship or relationship really begins? Maybe it’s when you first meet, or the first time you realize you genuinely enjoy being around each other. But I think we often miss something... the first time you reminisce together about how you met or your early moments.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/10/2026
In your message, let me know how much overall forensic experience you have, and how much work you've done in browser forensics specifically (and which browsers).
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 05/10/2026
We've got a new course releasing soon -- Browser Forensics for Security Analysts. I'm looking for a couple of reviewers at different experience levels who'd like to go through the course and can do so relatively quickly! Send me a message if you're interested.
210
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/10/2026
The more evidence sources you understand, the larger your investigative playing field becomes. As you understand how to think, you should also be expanding the field you operate in. #SOC #DFIR #CyberSecurity
030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 30/09/2026
Investigation Scenario 🔎 Windows Defender Event ID 5007 shows DisableRealtimeMonitoring changed from 0 to 1, yet MsMpEng.exe appears to still be running. What do you look for to investigate whether an incident occurred? #InvestigationPath #DFIR #SOC
210
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
Tools can make you a better analyst, but you have to be metacognitively aware enough to know where they fit in, where they have limits, and where it all might lead you astray. #DFIR #SOC #CyberSecurity
010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
It turns out that when you don't have the ability to evaluate investigative actions effectively, you can't build products or train LLMs effectively for that task either.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
So, I gave the same alert to the product lead and asked him to list the investigative questions he would pursue. The list he gave me wasn't very good either.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
I gave the tool a Suricata alert to work through. It wasted a lot of effort, sent the analyst down rabbit holes, and failed to resolve the questions that mattered most.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 24/09/2026
I was recently asked to advise on a product. The project lead showed me how his tool could take an alert, find the relevant data, and make investigative decisions based on what it found.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 23/09/2026
Investigation Scenario 🔎 Event ID 5136 on a DC shows msDS-KeyCredentialLink was modified on an old service account. No password reset occurred. What do you examine next to determine who added the credential and whether it was used? #InvestigationPath #DFIR #SOC
010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026
Among many who embrace it, that's leading to greater metacognitive awareness... people becoming more conscious of how they reason, not just what conclusions they reach. #DFIR #AI #LLM #Metacognition
020
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026
The more we try to understand what LLMs can and can’t do effectively, the more we’re forced to examine the cognitive processes we’ve traditionally taken for granted in ourselves.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026
How do analysts reason through uncertainty? How do we form hypotheses? What makes us notice one piece of evidence and ignore another? Where does intuition come from? How are human judgment and machine inference fundamentally different?
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 22/09/2026
I’ve taken a surprising number of calls lately from people wanting to understand how human reasoning differs from machine inference.
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
And here's the hands-on course: www.networkdefense.co/courses/hon...
networkdefense.co
Building Intrusion Detection Honeypots
Building Intrusion Detection Honeypots will teach you how to build, deploy, and monitor honeypots designed to catch intruders on your network.
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
Here's the CISA Report: www.cisa.gov/resources-t... Here's my Intrusion Detection Honeypots book: www.amazon.com/dp/17351883...
amazon.com
Intrusion Detection Honeypots: Detection through Deception
The foundational guide for using deception against computer network adversaries. When an attacker breaks into your network, you have a home-field advantage. But how do you use it? Intrusion Detection Honeypots is the foundational guide to building, deploying, and monitoring honeypots -- secu...
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
If you want to actually implement these ideas, I wrote the book Intrusion Detection Honeypots specifically around this philosophy. I also have a hands-on course that walks through designing and deploying IDHs in real environments.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
CISA’s report makes it clear that these techniques are valuable, especially when attackers use legitimate credentials and tools that make malicious activity harder to distinguish from normal behavior.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
The idea is simple: put something in your environment that nobody should touch, make it interesting to an attacker, and pay very close attention when somebody touches it. If you can control what an attacker sees and thinks, you can control what they do and find them.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
They’re low effort. They require very little tuning. And because legitimate users have no reason to interact with them, they can produce incredibly high-confidence alerts with very few false positives.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
I’ve been beating this drum for years: properly deployed internal honeypots are one of the best bargains in detection.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/09/2026
I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). #DFIR #IDS #Honeypots
110
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/09/2026
What do you look for next to determine what the user actually opened and whether malicious execution followed? #InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 16/09/2026
Investigation Scenario 🔎 A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds, but the referenced file never appears in the MFT.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/09/2026
#InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 09/09/2026
Investigation Scenario 🔎 Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could investigate. You only have Windows Event Logs (default config) and network sensor data. What do you look for to determine whether an incident occurred?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/09/2026
#InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 02/09/2026
Investigation Scenario 🔎 A user’s RecentDocs LNK file points to C:\Users\Public\Libraries\update.iso, mounted shortly before rundll32.exe launched update.dll from the new drive letter. The ISO is now gone. What do you look for to investigate whether an incident occurred?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/09/2026
But the pursuit of novelty can't be an excuse for ignorance of proven doctrine, either. Sometimes we need folks thinking outside the box, but more often, we just need to understand the box better. #DFIR #SOC #CyberSecurity
011
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 01/09/2026
I ask everyone who starts my Investigation Theory class, "What's a valuable trait or skill for an analyst to have?" Many say "thinking outside the box" And sometimes, unconventional solutions are exactly what’s needed.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/08/2026
#InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 25/08/2026
Investigation Scenario 🔎 While investigating a potentially compromised host, you've discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no knowledge of ever using this application. What do you look for to investigate whether the tool was used for malicious purposes?
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/08/2026
What do you look for to investigate whether an incident occurred? Extra credit for focusing on the distinct order of operations you would take. #InvestigationPath #DFIR #SOC
000
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 18/08/2026
Investigation Scenario 🔎 While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 system. The user claims they only connected a USB-C docking station.
Registry details show a USB mass storage device connected to a Windows 11 system, including installation date and device type.
100
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026
Investigation Scenario 🔎 You received an alert that one of your honeydocs was opened on a network other than your own. What do you look for to investigate whether an attacker exfiltrated this file from your network? #InvestigationPath #DFIR #SOC
111
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 11/08/2026
A whole bunch of people DM'd me about meeting Cliff Stoll in Vegas and I love that I've done things in my life that have folks wanting to share that specific joy with me. 💙😂 #cuckoosegg
030
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/07/2026
What do you look for to investigate whether an incident occurred? Bonus Exercise: List several of the potential explanations for this behavior #InvestigationPath #DFIR #SOC
010
Chris Sanders 🔎 🧠 @chrissanders88.bsky.social · 28/07/2026
Investigation Scenario 🔎 While reviewing Amcache.hve, you notice C:\Users\Public\Libraries\SyncHost.exe executed once, but no corresponding Prefetch file exists despite Prefetch being enabled. The file is not present at that location.
110