chronophage

95 Followers
243 Following
16 Posts

Cryptologue and Netsec-ologist. Formerly a genomics research apprentice, applying the same methods to infosec engineering and operations.

Friend to all animals large and small.

Twitter

To date I have not seen a better explanation for kernel based vulnerabilities the layperson and expert can both appreciate.

https://www.penny-arcade.com/comic/2024/03/25/venerable-and-inscrutable

Venerable And Inscrutable - Penny Arcade

Videogaming-related online strip by Mike Krahulik and Jerry Holkins. Includes news and commentary.

"I was just curious" - ffs - people, don't click phishy looking phish that is clearly phishing. Increasingly attackers don't care about your credentials, instead they are installing remote control software and simply taking what they want.

Your "curiosity" is the lure, the bait, and the hook.

In my porfolio of security skills I have all things you'd expect - reverse engineering, network analysis, forensics, vulnerability research, OS internals, SIEM searching, etc, etc. Or rather... I have everything you'd expect from someone who works in cybersecurity.

But if I had to honest, the single most useful skill I have, and this is winning by a mile, was know how to use Excel/Sheets

Knowing pivot tables, vlookups, conditionals, hot keys, macros, filters, how to make the data sing and dance, on a spreadsheet has saved my bacon so many times, I couldn't grep the number. If I could only pick 5 skills, spreadsheets would be top (and possibly also second)

Honorable mention - pandas and R studio, not used often, but absolutely clutch when needed

Oh right intros;
First and foremost: DFIR and security operations! I have mostly been in the higher ed space with some government thrown in.

In a former life I helped some incredibly talented genetics researchers at various labs do their research on HPCs (Ask me about bypassing qsub node constraints!).

My belief is that the conceptual methods of looking for de novo mutations indicative of a genetic disease is not entirely dissimilar from looking for IoC's in a sea of IT telemetry.

I aim to validate that belief or learn trying.
#introduction #genomic #infosec