Remote
Richard Bejtlich
@taosecurity@infosec.exchange
I was a captain in the United States Air Force who formally trained as an intelligence officer. I later worked in information warfare. I promoted the concept that "prevention eventually fails" in my first book (2004) and developed tactics, operations, and strategy to detect and respond to nation-state and criminal computer intrusions. I created the GE-CIRT and was Mandiant's first CISO. I currently advocate #NetworkSecurityMonitoring for @corelight@infosec.exchange. My latest books are here #ad https://amzn.to/3B2AcMc
2995 Followers
81 Following
18 Posts
Joined November 02, 2022
What do the kids say? “I was this days old when I learned” that Sysmon is available for Linux. https://github.com/microsoft/SysmonForLinux
Open post
Replying to
1
0
0
0
Open post
Every year on this day, I watch this brilliant music video and celebrate one of the greatest achievements of our civilization. https://youtu.be/BHIo6qwJarI?si=I8buXr-BscNOQlbn
Public Service Broadcasting - Go!
6
0
3
1
Open post
On average, the FreeBSD security team releases about 2 security advisories per month. AI has changed this.
In April, the project released 8 advisories, with 6 powered by AI. In May, the count decreased sightly to 7.
Today I took a look at the FreeBSD Security Advisory page to check the latest advisory count.
June saw the most number of advisories ever published in project history: 25.
See my latest blog for more: https://taosecurity.blogspot.com/2026/07/freebsd-released-most-security.html
6
1
6
0
Open post
I wrote a blog post about my new book. The book is free BTW, no email required. Blog post is here: https://corelight.com/cp/ndr-essentials
5
2
1
0
Open post
Mortal Kombat voice: “It has begun!”
“Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.”
https://huggingface.co/blog/security-incident-july-2026
2
0
1
0
Open post
Do you see that crescent at the far right of the image? That’s US! The larger crescent in the middle is the moon, and the left is the Artemis II mission spacecraft.
5
0
1
0
Open post
Open post
Open post
Replying to
@choomba@social.tchncs.de @b0rk@social.jvns.ca When a filter is tough to understand, you can dump the filter with -d and step through the compiled packet-matching code to see what it does. See https://taosecurity.blogspot.com/2004/09/understanding-tcpdumps-d-option-have.html and https://taosecurity.blogspot.com/2004/12/understanding-tcpdumps-d-option-part-2.html
1
0
0
0
Open post
Episode 18 of the Corelight podcast is live. I speak with Senior Sales Engineers Adam Donadeoto and Nico Roosenboom about their experiences at Locked Shields, the world’s largest international live-fire cyber defense exercise. We dive into the friction of defending a massive virtualized network against waves of red teamers.
https://www.youtube.com/playlist?list=PLBKbF72bCp2UtefR6_GhrKATP3tVD7Vev
https://open.spotify.com/show/2L2bkmbxaMxlz46xzhPNAH
https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362
0
0
0
0
Open post
Episode 20 of the Corelight podcast is live. This time, I'm the guest! Vince Stoffer interviews me about my newest book, NDR Essentials, which I wrote for Corelight. The book is free here, BTW: https://corelight.com/cp/ndr-essentials
https://www.youtube.com/playlist?list=PLBKbF72bCp2UtefR6_GhrKATP3tVD7Vev
https://open.spotify.com/show/2L2bkmbxaMxlz46xzhPNAH
https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362
0
0
0
0
Open post
Episode 24 of the Corelight podcast is live. I speak with Julie Parrish, CMO at Corelight, about how security professionals can communicate more effectively with CISOs, boards, and buyers who each measure success differently. Julie explains why practitioners should frame requests in terms of risk instead of technology, why CISOs need to connect security investments to reputation, compliance, and business continuity, and why marketers lose credibility when they lean on buzzwords, analogies, or FUD.
https://www.youtube.com/playlist?list=PLBKbF72bCp2UtefR6_GhrKATP3tVD7Vev
https://open.spotify.com/show/2L2bkmbxaMxlz46xzhPNAH
https://podcasts.apple.com/us/podcast/corelight-defendrs/id1843154362
0
0
1
0
Open post
Open post
Open post
Replying to
@TheDFIRReport@infosec.exchange I remember these tricks. I don’t remember if they used certutil before?
0
0
0
0
Open post
