Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Chris Sanders Information Security Analyst, Author, and Instructor ## Sitemaps - [XML Sitemap](https://chrissanders.org/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Blog](https://chrissanders.org/blog/) - [My Favorite Books of 2025](https://chrissanders.org/2025/12/my-favorite-books-of-2025/) - [A Standard for Human-Centered Investigation Playbooks](https://chrissanders.org/2025/06/human-centered-playbooks/) - [Milo and the Midnight Meteorite: A Children's Book](https://chrissanders.org/2025/08/milo-and-the-midnight-meteorite-a-childrens-book/) - [My Favorite Books of 2024](https://chrissanders.org/2025/01/my-favorite-books-of-2024/) - [My Favorite Books of 2023](https://chrissanders.org/2024/01/favorite-books-of-2023/) - [My Favorite Books of 2022](https://chrissanders.org/2023/01/favorite-books-2022/) - [Win My 2022 Golden Ticket for Free Training](https://chrissanders.org/2022/12/goldenticket22/) - [2022 Holiday Training Sale](https://chrissanders.org/2022/11/2022-holiday-training-sale/) - [So You Want To Write an Infosec Book?](https://chrissanders.org/2014/02/so-you-want-to-write-infosec-book/) - This article describes some of my experience and lessons learned over the past 9 years while writing four information security books. - [Win My Golden Ticket!](https://chrissanders.org/2021/12/goldenticket2021/) - [My Favorite Books of 2021](https://chrissanders.org/2021/12/favorite-books-2021/) - [A Cognitive Skills Assessment of Digital Forensic Analysts - My Doctoral Dissertation](https://chrissanders.org/2021/12/dissertation/) - [Infosec Practitioner's Guide to Philanthropy](https://chrissanders.org/2015/10/infosec-guide-to-philanthropy/) - This post describes ways that infosec practitioners can utilize their talents to give back to causes they care about. - [Building Intrusion Detection Honeypots Online Course](https://chrissanders.org/2021/04/idh-course/) - [Come Join Me at AND](https://chrissanders.org/2021/01/join-me-at-and/) - [My Favorite Books of 2020](https://chrissanders.org/2020/12/favorite-books-2020/) - [New Book: Intrusion Detection Honeypots](https://chrissanders.org/2020/09/idh-release/) - [The Call for Applied Research on Offensive Security Tool Release](https://chrissanders.org/2020/07/research-ost-release/) - [A Socratic Outline for Discussing the OST Release Debate](https://chrissanders.org/2020/07/socratic-ost/) - [Toward Applied Andragogy in Cyber Security Education](https://chrissanders.org/2020/06/toward-applied-andragogy/) - In this paper, I discuss the relationship between cyber security education and andragogy – the method and practice of teaching adult learners. - [Creative Choices: Developing a Theory of Divergence, Convergence, and Intuition in Security Analysts](https://chrissanders.org/2019/10/creative-choices-paper/) - [How Analysts Approach Investigations with Diagnostic Inquiry](https://chrissanders.org/2016/05/how-analysts-approach-investigations/) - [My Favorite Books of 2019](https://chrissanders.org/2019/12/favorite-books-2019/) - [Learning to Forget: Infosec’s Unfortunate Departure from Spaced Learning](https://chrissanders.org/2019/08/spaced-learning/) - This article discusses spaced learning and how private training providers’ departure from it unfavorably affects individual learning and the broader infosec industry. - [What's Next? Infosec Careers, Cognitive Dissonance, and Tours of Duty](https://chrissanders.org/2019/07/infosec-tour-of-duty/) - [Information Security Mental Models](https://chrissanders.org/2019/05/infosec-mental-models/) - Mental models frame how we think about the world. This article describes how they work and why we need more of them in information security. - [The Effects of Opening Move Selection on Investigation Speed](https://chrissanders.org/2016/09/effects-of-opening-move-investigation-speed/) - This article discusses how the first move you make during an investigation can affect how quickly you come to a conclusion. - [New Course - Practical Threat Hunting](https://chrissanders.org/2019/03/new-course-practical-threat-hunting/) - [The Cult of Passion](https://chrissanders.org/2017/06/the-cult-of-passion/) - [Perspective on the State of Computer Science in 2018 Report](https://chrissanders.org/2018/12/perspective-code-cs-access-2018/) - [My Favorite Books of 2018](https://chrissanders.org/2018/12/favorite-books-2018/) - This post describes my favorite books I've read all year and what I liked about them. - [Content Matching Detection and Additional Outputs](https://chrissanders.org/2018/12/additional-outputs-content-matching/) - [The Role of Evidence Intention](https://chrissanders.org/2018/10/the-role-of-evidence-intention/) - [Analyzing Large Capture Files 4: Whittling with Filters](https://chrissanders.org/2018/06/large-captures4-filter-whittling/) - [Packet Analysis Workshop in Augusta, GA](https://chrissanders.org/2018/06/packet-workshop-augusta/) - [Analyzing Large Capture Files Part 1 - Colorizing Conversations in Wireshark](https://chrissanders.org/2018/05/large-captures1-colorizing-wireshark/) - This article begins a series on how to handle large packet capture files that may be overwhelming. The first strategy I describe is how to use Wireshark to colorize individual conversations. - [Analyzing Large Capture Files 3 - Distillation with Security Tools](https://chrissanders.org/2018/05/large-captures3-distillation/) - This is the third article in a series on how to handle large packet capture files that may be overwhelming. I focus on using security tools like Suricata, Bro, and PRADS to distill PCAPs down to key events. - [Investigation Theory Coming to Charlottesville, VA](https://chrissanders.org/2018/05/investigation-theory-charlottesville/) - I'm bringing my Investigation Theory course to Charlottesville, VA on June 19th and 20th. - [Source Code S2: Episode 6 - Jennifer Kolde](https://chrissanders.org/2018/01/source-code-s2-episode-6-jennifer-kolde/) - [Cuckoo's Egg - Week 5 Notes](https://chrissanders.org/2018/01/cuckoos-egg-week-5-notes/) - [Cuckoo's Egg - Week 6 Notes](https://chrissanders.org/2018/01/cuckoos-egg-week-6-notes/) - [Source Code S2: Episode 7 - Michael W. Lucas](https://chrissanders.org/2018/01/source-code-s2-episode-7-michael-w-lucas/) - [Cuckoo's Egg - Week 7 Notes](https://chrissanders.org/2018/01/cuckoos-egg-week-7-notes/) - [Cuckoo's Egg - Week 8 Notes](https://chrissanders.org/2018/02/cuckoos-egg-week-8-notes/) - [The Complete Cuckoo's Egg Online Course Available for Free](https://chrissanders.org/2018/02/cuckoos-egg-course-download/) - [Source Code S2: Episode 8 - Gwen Betts](https://chrissanders.org/2018/02/source-code-s2-episode-8-gwen-betts/) - [Analyzing Large Capture Files Part 2 - Protocol Hierarchy](https://chrissanders.org/2018/05/large-captures2-proto-hierarchy/) - This is the second article in a series on how to handle large packet capture files that may be overwhelming. I focus on using protocol hierarchies to help ask great questions. - [Security Onion Cheat Sheet](https://chrissanders.org/2017/06/security-onion-cheat-sheet/) - [The Cuckoo's Egg Decompiled: An Introduction to Information Security](https://chrissanders.org/2017/09/cuckoos-egg-course/) - [Cuckoo's Egg - Week 3 Notes](https://chrissanders.org/2017/11/cuckoos-egg-week-3-notes/) - [Cuckoo's Egg - Week 2 Notes](https://chrissanders.org/2017/11/cuckoos-egg-week-2-notes/) - [Cuckoo's Egg - Week 1 Notes](https://chrissanders.org/2017/11/cuckoos-egg-week-1-notes/) - [Video: Building an NSM Lab](https://chrissanders.org/2016/03/video-building-an-nsm-lab/) - In this one hour video I discuss the importance of an NSM lab and go through a systematic approach to building your own. - [Source Code S2: Episode 5 - Grady Summers](https://chrissanders.org/2017/12/source-code-s2-episode-5-grady-summers/) - [Cuckoo's Egg - Week 4 Notes](https://chrissanders.org/2017/12/cuckoos-egg-week-4-notes/) - [Help Me Introduce Rural 100,000 Students to Technology](https://chrissanders.org/2017/12/100000-students/) - Help Me Introduce Rural 100,000 Students to Technology - [Source Code S2: Episode 4 - Sergio Caltagirone](https://chrissanders.org/2017/11/source-code-s2-episode-4-sergio-caltagirone/) - [Source Code S2: Episode 3 - Haroon Meer](https://chrissanders.org/2017/11/source-code-s2-e3-haroon-meer/) - [The AND Student Charitable Profit Sharing Program](https://chrissanders.org/2017/11/and-charitable-sharing/) - [Forcing Attacker Decisions](https://chrissanders.org/2017/11/forcing-attacker-decisions/) - This article discusses how the strategic introduction of information at the right time can force network attackers into hasty and poor decision-making. - [Source Code S2: Episode 2 - Rick Holland](https://chrissanders.org/2017/10/source-code-s2-episode-2-rick-holland/) - [Source Code S2: Episode 1 - Richard Bejtlich](https://chrissanders.org/2017/10/source-code-s2-episode-1-richard-bejtlich/) - [Gaining Technical Experience with Deliberate Practice](https://chrissanders.org/2017/10/deliberate-practice/) - This post discusses how experts accelerate the accumulation of experience through deliberate practice. - [New Online Course: ELK for Security Analysis](https://chrissanders.org/2017/07/new-course-elk-for-security-analysis/) - [Rural Tech Fund Shirts](https://chrissanders.org/2017/07/rtf-shirts/) - [Source Code S1: Episode 8 - Jason Smith](https://chrissanders.org/2017/07/source-code-s1-episode-8-jason-smith/) - [Source Code S1: Episode 7 - Bill Pollock](https://chrissanders.org/2017/06/source-code-s1-episode-7-bill-pollock/) - [Video: Tracking Investigations with Timelines](https://chrissanders.org/2016/06/video-tracking-investigations-timelines/) - [Source Code S1: Episode 6 - Matt Swann](https://chrissanders.org/2017/06/source-code-s1-episode-6-matt-swann/) - [Investigation Theory Course On Site in Augusta, GA!](https://chrissanders.org/2017/06/investigation-theory-augusta/) - [Source Code S1: Episode 5 - Gerald Combs](https://chrissanders.org/2017/05/source-code-s1-episode-5-gerald-combs/) - [5 Human-Centered Takeaways from the SANS SOC Survey](https://chrissanders.org/2017/05/5-human-centered-takeaways-from-the-sans-soc-survey/) - [Source Code S1: Episode 4 - Mike Poor](https://chrissanders.org/2017/05/source-code-s1-e4-mike-poor/) - [Know Your Bias - Availability Heuristic](https://chrissanders.org/2017/05/know-your-bias-availability-heuristic/) - [Practical Packet Analysis Photo Contest](https://chrissanders.org/2017/05/ppa-photo-contest/) - [Source Code S1: Episode 3 - Magen Wu](https://chrissanders.org/2017/04/source-code-s1-episode-3-magen-wu/) - [Source Code S1: Episode 2 - Doug Burks](https://chrissanders.org/2017/04/podcast-s1e2-dougburks/) - [Time, Straight Lines, and the Next Step](https://chrissanders.org/2017/04/time-straight-lines-and-next-step/) - [Introducing the Source Code Podcast](https://chrissanders.org/2017/03/introducing-source-code-podcast/) - [Announcing the Practical Packet Analysis Online Course](https://chrissanders.org/2017/03/announcing-the-practical-packet-analysis-online-course/) - [Investigation Case Management with TheHive](https://chrissanders.org/2017/03/case-management-the-hive/) - This post provides an overview of The Hive, a case management system used for the investigation of information security threats and incidents. - [Announcing the Investigation Theory Online Course](https://chrissanders.org/2016/12/announcing-investigation-theory-course/) - [Practical Packet Analysis 3rd Edition Released!](https://chrissanders.org/2017/03/ppa3-release/) - [Increase Security Reporting with Contact Cards](https://chrissanders.org/2017/03/security-contact-cards/) - [Training Course Scholarships](https://chrissanders.org/2017/03/training-course-scholarships/) - [Know Your Bias - Anchoring](https://chrissanders.org/2017/01/know-your-bias-2-anchoring/) - [Know your Bias - Foundations](https://chrissanders.org/2017/01/know-your-bias-1-foundations/) - This post is the first in a series that discusses bias and how it can negatively affect the investigation process. - [Making an Impact with Local Security Conferences](https://chrissanders.org/2016/11/impact-security-conferences/) - [Three Useful SOC Dashboards](https://chrissanders.org/2016/10/three-useful-soc-dashboards/) - This post outlines three dashboards you can use in a SOC that are actually useful to analysts. - [Accelerating Experience with Investigation Heuristics](https://chrissanders.org/2016/05/accelerating-experience-with-investigation-heuristics/) - This article explores how expert analysts use rule-based reasoning to perform investigations, and how heuristics can be used to accelerate experience. - [Writing for Security: Action Items that Provoke Change](https://chrissanders.org/2016/03/writing-for-hackers-5-action-items-change/) - [Writing for Security: Making People Give a Damn](https://chrissanders.org/2016/03/writing-for-hackers-4-making-people-give-a-damn/) - In this post, I discuss why it's important to connect with your readers primary and secondary needs in order to make them care about your content. - [Writing for Security: Making it Matter to You](https://chrissanders.org/2016/03/writing-for-hackers-3-making-it-matter-to-you/) - [Writing for Security: Why You Fear It](https://chrissanders.org/2016/03/writing-for-hackers-2-why-you-feair-it/) - [Writing for Security: Why You Hate It](https://chrissanders.org/2016/03/writing-for-hackers-1-why-you-hate-it/) - In this article, I introduce a new series on technical writing for security and review why most people hate the technical writing process. - [Mailing List Availability](https://chrissanders.org/2016/03/newsletter-availability/) - [Survey: Technical Writing Pain Points](https://chrissanders.org/2016/02/survey-security-writing-pain-points/) - I'd love to hear from you for an upcoming series of posts. What do you dislike about technical writing the most? - [The Role of Curiosity in Security Investigations](https://chrissanders.org/2016/01/curiosity-in-security-investigations/) - In this post I will talk about curiosity as a trait, how it manifests in the investigative process, how it’s measured, and whether it’s a teachable skill. - [Research Call for Security Investigators](https://chrissanders.org/2016/01/call-for-investigators/) - [Launching Makerspaces Across Rural America](https://chrissanders.org/2015/11/mara-launch/) - I'm excited to announce the latest Rural Technology Fund initiative, Makerspaces Across Rural America, where we hope to build ten makerspaces is rural classrooms. - [Inattentional Blindness in Security Investigations](https://chrissanders.org/2015/08/inattentional-blindness/) - This article explores the concept of inattentional blindness and how it can affect security investigations and the analysts who conduct them. - [Information Security Incident Morbidity and Mortality (M&M)](https://chrissanders.org/2012/08/information-security-incident-morbidity-and-mortality/) - This article discusses the use of Morbidity and Mortality (M&M) conferences, a medical concept, for the purpose of infosec learning related to incidents. - [Investigations and Prospective Data Collection](https://chrissanders.org/2015/06/investigations-prospective-data-collection/) - This post examines how physicians use prospective data collection to get from symptoms to diagnosis, and how security investigations can use a similar approach. - [On the Importance of Questions in an Investigation](https://chrissanders.org/2015/05/questions-in-investigations/) - A successful information security investigation can hinge on asking the right questions. This short post cites some reasons why that is true. - [Technical Book Purchases Making a Difference](https://chrissanders.org/2015/05/15-mid-year-donations/) - [Working Memory and the Visual Investigative Hypothesis](https://chrissanders.org/2015/04/visual-investigative-hypothesis/) - Visual investigative hypothesis states that security analysts are more efficient, and more likely to arrive at a conclusion based on an accurate representation of events that occurred when they are able to visualize the relationships that represent a network compromise and build a mental picture of an attacker moving through a network. - [The Value of Watching Game Tape](https://chrissanders.org/2015/03/the-value-of-watching-game-tape/) - [Evolving Towards an Era of Analysis](https://chrissanders.org/2014/09/era-of-analysis/) - [Investigating Like a Chef](https://chrissanders.org/2015/01/investigating-like-a-chef/) - In this post I talk about some characteristics of professional chefs, and lessons that can be learned and applied to information security investigations. - [Teaching Good Investigation Habits Through Reinforcement](https://chrissanders.org/2015/01/teaching-good-investigation-habits-through-reinforcement/) - In this blog post I share thoughts related to how organisms learn through operant conditioning, and how it applies to security investigations. - [Perception, Cognition, and the Notion of “Real Time” Detection and Analysis](https://chrissanders.org/2014/12/perception-cognition-and-real-time-detection-analysis/) - [Theory of Multiple Intelligences for Security Analysts - Initial Thoughts](https://chrissanders.org/2014/12/initial-thoughts-theory-of-multiple-intelligences-for-analysts/) - [Charleston ISSA Slides: Using Canary Honeypots for NSM](https://chrissanders.org/2014/11/slides-using-canary-honeypots-for-nsm/) - [Introducing FlowBAT, the Flow Analysis GUI](https://chrissanders.org/2014/10/introducing-flowbat/) - [MIRCon 2014 Slides: Applied Detection and Analysis with Flow Data](https://chrissanders.org/2014/10/mircon-2014-slides/) - [BSides Augusta 2014 Slides and Video - Defeating Cognitive Bias and Developing Analytic Technique](https://chrissanders.org/2014/10/bsides-augusta-2014-slides-video/) - [Practical Packet Analysis 3rd Edition Research](https://chrissanders.org/2014/08/practical-packet-analysis-3rd-edition-research/) - [Applied NSM Blog Post: The NSM Analyst's Notebook](https://chrissanders.org/2014/03/ansm-blog-post-the-nsm-analysts-notebook/) - [Applied NSM Dedication and Acknowledgements](https://chrissanders.org/2013/12/applied-nsm-dedication-and-acknowledgements/) - [Applied NSM Blog Post: Using Wireshark Host Files for Quicker Analysis](https://chrissanders.org/2013/12/ansm-blog-post-wireshark-host-files/) - [Charleston ISSA Chapter Forming](https://chrissanders.org/2013/07/charleston-issa-forming/) - [Raspberry Pi Donations for Public Schools](https://chrissanders.org/2013/06/raspberry-pi-donations/) - I'm donating 100 Raspberry Pi devices to public schools. Here is how you can help. - [My Testimony](https://chrissanders.org/2013/04/my-testimony/) - [Applied Network Security Monitoring, the book!](https://chrissanders.org/2013/02/applied-nsm-the-book/) - I'm thrilled to announce my newest project, Applied Network Security Monitoring, the book, along with my co-authors Liam Randall and Jason Smith. - [4 Ideas for Operationalizing Honeypots](https://chrissanders.org/2012/03/4-ideas-for-operationalizing-honeypots/) - This post discusses four ideas that could make honeypots a viable player in a network defense strategy. - [NSM Collection vs. Detection](https://chrissanders.org/2012/02/nsm-collection-vs-detection/) - Which is more important in terms of NSM, collection or detection? In this article I discuss both sides and why I think collection is most critical. - [Packet School 101 - Part 5](https://chrissanders.org/2006/09/packet-school-101-part-5/) - [Packet School 101 - Part 4](https://chrissanders.org/2006/07/packet-school-101-part-4/) - [Packet School 101 - Part 3.5](https://chrissanders.org/2006/07/packet-school-101-part-35/) - [Packet School 101 - Part 2](https://chrissanders.org/2006/06/packet-school-101-part-2/) - [Packet School 101 - Part 3](https://chrissanders.org/2006/07/packet-school-101-part-3/) - [Packet School 101 - Part 1](https://chrissanders.org/2006/06/packet-school-101-part-1/) - [Differential Diagnosis of Network Security Monitoring Events](https://chrissanders.org/2012/01/differential-diagnosis-nsm/) - This article discusses the use of a common medical diagnostic method called differential diagnosis and how it can be applied to network security monitoring. - [Packet Carving with SMB and SMB2](https://chrissanders.org/2011/11/packet-carving-with-smb-and-smb2/) - This article discusses the art of carving files from SMB and SMB2 traffic. - [Using Application Layer Metadata for Network Security Monitoring](https://chrissanders.org/2011/09/using-application-layer-metadata-for-network-security-monitoring/) - Using Application Layer Metadata for Network Security Monitoring can have a very positive impact on your intrusion detection capability. This article details the concept behind application layer metadata along with how to generate the PSTR data format to utilize this data type. - [GFIRST 2011 Presentation Slides, Code, and Thoughts](https://chrissanders.org/2011/08/gfirst-2011-presentation-slides-code-and-thoughts/) - [The 10 Commandments of Intrusion Analysis](https://chrissanders.org/2011/01/the-10-commandments-of-intrusion-analysis/) - [My Review of SANS FOR610: Reverse Engineering Malware](https://chrissanders.org/2011/04/my-review-of-sans-for610-reverse-engineering-malware/) - [Collecting Threat Intelligence](https://chrissanders.org/2011/02/collecting-threat-intelligence/) - [Sanitizing PCAP Files for Public Distrubution](https://chrissanders.org/2010/12/sanitizing-pcap-files-for-public-distrubution/) - [Using a Tap for Packet Analysis](https://chrissanders.org/2009/04/using-a-tap-for-packet-analysis/) - [Keeping Capture Files Manageable](https://chrissanders.org/2009/04/keeping-capture-files-manageable/) - [Understanding Man-In-The-Middle Attacks](https://chrissanders.org/2010/06/understanding-man-in-the-middle-attacks/) - [Viewing Packet Captures Online with CloudShark](https://chrissanders.org/2010/06/viewing-packet-captures-online-with-cloudshark/) - [Packet Analysis Interview by SearchNetworking.com](https://chrissanders.org/2007/08/packet-analysis-interview-by-searchnetworkingcom/) - [Using ARP Cache Poisoning for Packet Analysis](https://chrissanders.org/2008/04/using-arp-cache-poisoning-for-packet-analysis/) - [Announcing the Rural Technology Fund](https://chrissanders.org/2009/05/announcing-the-rural-technology-fund/) - [Packet School 201 - Part 1 (ARP)](https://chrissanders.org/2007/12/packet-school-201-part-1-arp/) - [PPA Book Acknowledgements](https://chrissanders.org/2007/05/ppa-book-acknowledgements/) ## Pages - [Home](https://chrissanders.org/) - Security Analyst, Cognitive Psychology PhD Researcher, Author, and BBQ Pit Master - [AND Office Hours](https://chrissanders.org/officehours/) - [Links](https://chrissanders.org/links/) - [The Cuckoo's Egg Decompiled Course](https://chrissanders.org/training/cuckoosegg/) - The Cuckoo's Egg Decompiled is an online course designed to provide an introduction to information security, as told through the lens of Cliff Stoll's "The Cuckoo's Egg" book. - [About](https://chrissanders.org/about/) - [Investigation Theory Training](https://chrissanders.org/training/investigationtheory/) - [Publications](https://chrissanders.org/publications/) - [Contact](https://chrissanders.org/contact/) - [Training](https://chrissanders.org/training/) - [Building Intrusion Detection Honeypots Training](https://chrissanders.org/training/honeypots/) - [Effective Security Writing Training](https://chrissanders.org/training/writing/) - [Practical Threat Hunting Training](https://chrissanders.org/training/threat-hunting-training/) - [Resume](https://chrissanders.org/resume/) - [Top Posts](https://chrissanders.org/about/hits/) - [Practical Packet Analysis Training](https://chrissanders.org/training/packetanalysis/) - [ELK for Security Analysis Training](https://chrissanders.org/training/elk/) - [Mailing List](https://chrissanders.org/list/) - If you like my content or books, consider signing up for my mailing list. You'll get access to exclusive content, training videos, and publication discount codes. - [Podcast](https://chrissanders.org/podcast/) - Source Code is an information security podcast that’s all about education. We are focused on the people that push information security forward and battle in the trenches every day. - [Applied Network Security Monitoring](https://chrissanders.org/appliednsm/) - [Packets](https://chrissanders.org/packet-captures/) - [My Testimony](https://chrissanders.org/mytestimony/) - [Charleston](https://chrissanders.org/charleston/) ## Categories - [Intrusion Detection](https://chrissanders.org/category/ids/) - [Packet Analysis](https://chrissanders.org/category/packet-analysis/) - [Personal](https://chrissanders.org/category/personal/) - [Publications](https://chrissanders.org/category/publications/) - [Training](https://chrissanders.org/category/training/) - [Network Security](https://chrissanders.org/category/network-security/) - [Charity](https://chrissanders.org/category/charity-2/) - [Network Security Monitoring](https://chrissanders.org/category/network-security-monitoring/) - [Honeypots](https://chrissanders.org/category/honeypots/) - [Psychology](https://chrissanders.org/category/psychology/) - [Investigations](https://chrissanders.org/category/investigations/) - [Analysis](https://chrissanders.org/category/analysis-2/) - [Intelligence](https://chrissanders.org/category/intelligence/) - [Writing](https://chrissanders.org/category/writing/) - [Hunting](https://chrissanders.org/category/hunting/) - [Podcast](https://chrissanders.org/category/podcast/) - [Detection](https://chrissanders.org/category/detection/) - [Education](https://chrissanders.org/category/education/) - [Career](https://chrissanders.org/category/career/) - [Hiring](https://chrissanders.org/category/hiring/) ## Tags - [Network Security](https://chrissanders.org/tag/security/) - [analysis](https://chrissanders.org/tag/analysis/) - [arp](https://chrissanders.org/tag/arp/) - [charity](https://chrissanders.org/tag/charity/) - [dns](https://chrissanders.org/tag/dns/) - [microsoft](https://chrissanders.org/tag/microsoft/) - [network](https://chrissanders.org/tag/network/) - [packet](https://chrissanders.org/tag/packet/) - [packets](https://chrissanders.org/tag/packets/) - [reverse](https://chrissanders.org/tag/reverse/) - [wireshark](https://chrissanders.org/tag/wireshark/) - [sans](https://chrissanders.org/tag/sans-2/) - [Rural Technology Fund](https://chrissanders.org/tag/rural-technology-fund/) - [man in the middle](https://chrissanders.org/tag/man-in-the-middle/) - [SSL](https://chrissanders.org/tag/ssl/) - [tcprewrite](https://chrissanders.org/tag/tcprewrite/) - [tcpreplay](https://chrissanders.org/tag/tcpreplay/) - [tcpdump](https://chrissanders.org/tag/tcpdump/) - [threat](https://chrissanders.org/tag/threat/) - [intelligence](https://chrissanders.org/tag/intelligence/) - [intrusion](https://chrissanders.org/tag/intrusion/) - [detection](https://chrissanders.org/tag/detection/) - [malware](https://chrissanders.org/tag/malware/) - [engineering](https://chrissanders.org/tag/engineering/) - [gfirst](https://chrissanders.org/tag/gfirst/) - [uscert](https://chrissanders.org/tag/uscert/) - [rural tech fund](https://chrissanders.org/tag/rural-tech-fund/) - [us-cert](https://chrissanders.org/tag/us-cert/) - [soc](https://chrissanders.org/tag/soc/) - [pstr](https://chrissanders.org/tag/pstr/) - [application](https://chrissanders.org/tag/application/) - [layer](https://chrissanders.org/tag/layer/) - [http](https://chrissanders.org/tag/http/) - [metadata](https://chrissanders.org/tag/metadata/) - [nsm](https://chrissanders.org/tag/nsm/) - [smb](https://chrissanders.org/tag/smb/) - [smb2](https://chrissanders.org/tag/smb2/) - [server message block](https://chrissanders.org/tag/server-message-block/) - [file transfer](https://chrissanders.org/tag/file-transfer/) - [carving](https://chrissanders.org/tag/carving/) - [extracting](https://chrissanders.org/tag/extracting/) - [windows networking](https://chrissanders.org/tag/windows-networking-2/) - [network forensics](https://chrissanders.org/tag/network-forensics/) - [rtf](https://chrissanders.org/tag/rtf/) - [monitoring](https://chrissanders.org/tag/monitoring/) - [events](https://chrissanders.org/tag/events/) - [collection](https://chrissanders.org/tag/collection/) - [differential](https://chrissanders.org/tag/differential/) - [technique](https://chrissanders.org/tag/technique/) - [approach](https://chrissanders.org/tag/approach/) - [style](https://chrissanders.org/tag/style/) - [network security monitoring](https://chrissanders.org/tag/network-security-monitoring-2/) - [honeypot](https://chrissanders.org/tag/honeypot/) - [honeyd](https://chrissanders.org/tag/honeyd/) - [honeynet](https://chrissanders.org/tag/honeynet/) - [medical](https://chrissanders.org/tag/medical/) - [ir](https://chrissanders.org/tag/ir/) - [incident response](https://chrissanders.org/tag/incident-response/) - [information security](https://chrissanders.org/tag/information-security/) - [ansm](https://chrissanders.org/tag/ansm/) - [testimony](https://chrissanders.org/tag/testimony/) - [raspberry pi](https://chrissanders.org/tag/raspberry-pi/) - [donation](https://chrissanders.org/tag/donation/) - [Charleston ISSA](https://chrissanders.org/tag/charleston-issa/) - [Intrusion Detection](https://chrissanders.org/tag/ids/) - [Network Security](https://chrissanders.org/tag/network-security/) - [idh](https://chrissanders.org/tag/idh/) - [honeypot course](https://chrissanders.org/tag/honeypot-course/)