The Problem is the People, but Which People?
In my second job out of college, my boss' boss would often say, "Wherever you go there's always a problem and the problem is always the people." I wondered to myself, "Yeah, but which people?"In my previous post in this series, I recounted how reading Sheryl Sandberg's book, Lean In: Women, ... Read More
Lean In for Yourself
Small family farming is a labor intensive way to go broke. When I was young I spent some weeks each summer with my grandparents. As farmers and cattle ranchers, my grandparents scratched out an existence. My grandpa was up before dawn feeding cattle and out working fields of corn, milo, sorghum, soybeans, ... Read More
RIP Grant W. Dotson — A dear friend
It's been a rough day. About 18 months ago a friend of mine from high school posted a Go FundMe on Facebook for a mutual friend who was battling cancer. This mutual friend was someone I'd been very close to in elementary and middle school. As happens, we remained friends, but ... Read More
Hunting injected processes by the modules they keep
A relatively recent post showed how Metasploit's Meterpreter module made some noise on endpoints when the migrate command was used to move the agent code into a legitimate process, spoolsv.exe in our example.One of the things we saw in that post was that when the agent migrates, it uses commonplace ... Read More
Analyzing an Instance of Meterpreter’s Shellcode
In my previous post on detecting and investigating Meterpreter's Migrate functionality, I went down a rabbit hole on the initial PowerShell attack spawned by and Excel macro. In that payload was a bit of shellcode and I mentioned that I'd like to return to it at some point in the ... Read More
The last 1717 days
I mentioned on LinkedIn yesterday that I'm looking for a new role. For recruiters and interested parties, I thought I should provide some background about what I've been doing for the last four and a half years.I left Microsoft back in September of 2015. It was a difficult decision. I ... Read More
Ode to Kasiski
00101110 00000000 00000110 00001101 00000011 00011000 00001101 01010100 00001000 00001101 0001001000000001 00011000 00000111 00000001 00010110 01001101 00001110 00010010 01001001 00010111 0001101100001000 01000001 00010111 00000001 00010101 00000101 00000100 00000110 01001001 00010111 0001011000010101 00010101 01010100 00000001 00001011 01001101 00010101 00011100 00000000 00010000 0101001100011101 00001110 00000111 00011100 01000101 00001110 00000000 00011010 01001001 00001111 ... Read More
trustedsignal — blog 2019-04-19 08:46:00
I was recently reminded of Rear Admiral Grace Hopper remark:The most damaging phrase in the language is “We’ve always done it this way!”When I was in high school I was a lifeguard at a waterpark with a wave pool, water slides, a cave with a waterfall, a pair of monorails ... Read More
Kansa’s Stafford release: More capable, more forensically sound, more flexible
Over the last few months significant changes have been pushed to Kansa's next branch. Those changes were very recently pushed to master, then packaged into the Stafford release. I mentioned in the release notes I would have a longer post here about the changes. There have been more than 130 commits ... Read More
Cracking repeating XOR key crypto
My last post here, XOR'd play: Normalized Hamming Distance, was a lengthy bit about the reliability of Normalized Hamming Distance to determine the size of a repeating XOR key that was used to encrypt a string of text and was based on my experience working on the Matasano Crypto Challenges at ... Read More

