Blueprint: Build the Best in Cyber Defense

Blueprint: Build the Best in Cyber Defense

By SANS InstituteTechnology
Download on the App Store

Blueprint: Build the Best in Cyber Defense episodes

  • Dean Parsons: Cyber Security for OT and ICS

    With ransomware and other highly disruptive attacks on the rise, there are few systems more important to defend than our critical infrastructure and ICS equipment. How should we think about defending these systems vs our typical IT network though? In this episode, Dean Parsons is here to give us that answer. 

    Our Guest - Dean Parsons

    Dean brings over 20 years of technical and management experience to the classroom. He has worked in both Information Technology and Industrial Control System (ICS) Cyber Defense in critical infrastructure sectors such as telecommunications, and electricity generation, transmission, distribution, and oil & gas refineries, storage, and distribution. Dean is an ambassador for defending industrial systems and an advocate for the safety, reliability, and cyber protection of critical infrastructure. His mission as an instructor is to empower each of his students, and he earnestly preaches that “Defense is Do-able!” 

    Over the course of his career, Dean’s accomplishments include establishing entire ICS security programs for critical infrastructure sectors, successfully containing and eradicating malware and ransomware infections in electricity generation and manufacturing control networks, performing malware analysis triage and ICS digital forensics, building converged IT/OT incident response and threat hunt teams, and conducting ICS assessments in electric substations, oil and gas refineries, manufacturing, and telecommunications networks. 

    A SANS Certified Instructor, Dean teaches ICS515: ICS Visibility, Detection, and Response and is a co-author of the new SANS Course ICS418: ICS Security Essentials for Managers. Dean is a member of the SANS GIAC Advisory Board and holds many cybersecurity professional certifications including the GICSP, GRID, GSLC, and GCIA, as well as the CISSP®. He is a proud native of Newfoundland and holds a BS in computer science from Memorial University of Newfoundland.


    Follow Dean Parsons

    Twitter: https://twitter.com/deancybersec

    LinkedIn: https://www.linkedin.com/in/dean-parsons-cybersecurity/


    Resources mentioned in this episode

    OSINT / Site-visit Cheat Sheet

    https://www.sans.org/posters/ics-site-visit-plan/


    ICS Cyber Kill Chain Whitepaper:

    https://www.sans.org/white-papers/36297/?msc=blog-ics-library


    ICS specific Network Security Monitoring:

    https://www.sans.org/posters/industrial-network-security-monitoring/


    Top 5 ICS Incident Response Tabletops

    https://www.sans.org/blog/top-5-ics-incident-response-tabletops-and-how-to-run-them/


    My weekly ICS Defense Force LiveStream

    https://www.youtube.com/playlist?list=PLjoUWqjR7qXhdZIcC8LgEBogrTyeoKqRT


    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    57 min
  • John Hubbard: Your Top Cyber Defense Questions Answered from Seasons 1 + 2

    It's a special mailbag episode from John Hubbard! After two seasons, John asked the listeners what questions they had for him.  He touched on the current XDR trend, how other teams can support SOC activities, defining security mindset, and more. 

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    21 min
  • John Hubbard: Key lessons and takeaways from Blueprint Season 2 + A Special Announcement!

    In this solo episode to wrap up season 2, John discusses some of the key takeaways from the guests interviwed throughout this year, and has some very exciting news for all blue teamers on a brand new GIAC certification. ;)

    Link: (GIAC GSOC LINK HERE)

    John is a Security Operations Center (SOC) consultant and speaker, a Certified SANS instructor, and the course author of two SANS courses, SEC450: Blue Team Fundamentals - Security Operations and Analysis and MGT551: Building and Leading Security Operations Centers.

    Follow John
    Twitter: @SecHubb
    YouTube: youtube.com/user/jhub908
    LinkedIn: in/johnlhubbard

    All Blueprint Podcast Episodes: sans.org/blueprint-podcast

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    23 min
  • Mark Morowczynski & Thomas Detzner: Microsoft Incident Response Playbooks

    We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won't want to miss it.

    Our Guests: Thomas Detzner and Mark Morowczynski
    Thomas Detzner is a Project Leader  for Microsoft, creating guidance for Azure AD IR.

    Mark Morowczynski (@markmorow) is a Principal Program Manager on the customer success team in the Microsoft Identity division. He spends most of his time working with customers on their deployments of Azure Active Directory. He can be frequently found on Twitter as @markmorow arguing about baseball and making sometimes funny gifs.

    Links:
    https://aka.ms/irplaybooks - Playbooks discussed in this episode
    https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor-stream-logs-to-event-hub#access-data-from-your-event-hub - Azure Event Hub
    https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093 - Security Baslines
    https://www.microsoft.com/en-us/download/details.aspx?id=52630 - Security Auditing and Monitoring Reference

    Sponsor's Note:
    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450! Hope to see you in class!
    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    43 min
  • AJ Yawn: Cloud, Compliance and Automating Security

    Compliance and audit checks can be painful, and that's before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security concepts and tools that can help your team boost visibility and reduce user permissions to help prevent breaches before they happen. In addition, we discuss what a good compliance audit should be, and how to turn audits from painful to incredibly valuable.

    Resources mentioned in this episode:
    - AWS CloudTrail: https://aws.amazon.com/cloudtrail/
    - AWS Well-Architected Framework:https://aws.amazon.com/architecture/well-architected/
    - AWS Config: https://aws.amazon.com/config
    - AWS Organizations:https://aws.amazon.com/organizations/
    - AWS Service Control Policies (SCP): https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

    Our Guest - AJ Yawn
    AJ Yawn is the Co-Founder and CEO of ByteChek. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.

    AJ advises startups on cloud security and serves on the Board of Directors of the ISC2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and ISC2.

    Sponsor's Note:
    Support for the Blueprint podcast comes from the SANS Institute.

    Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!

    Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we've got you covered, no matter what your specialty.

    With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.

    Check out the constantly growing list of available courses at sansurl.com/blueteamops
    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    56 min
  • Jamie Williams: Adversary Emulation

    There are numerous ways to test your SOC's detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus on arguably one of the most important - adversary emulation. In this episode we speak with Jamie Williams from the MITRE ATT&CK team about why adversary emulation is important, how it works, how you can get started regardless of the size of your team, and how to track and run an adversary emulation test.

    Our guest: Jamie Williams
    Jamie Williams is a Principal Adversary Emulation Engineer for the MITRE Corporation where he works on various exciting efforts involving security operations and research, specializing in adversary emulation and behavior-based detections. He also leads teams that help shape and deliver the “adversary-touch” within ATT&CK® and ATT&CK Evaluations.

    Follow Jamie Williams on Twitter (@jamieantisocial) and LinkedIn (/in/jamie-williams-108369190).

    Sponsor's Note
    Support for the Blueprint podcast comes from the SANS Institute.

    Since the debut of SEC450, we’ve always had students interested in a matching course covering the management and leadership aspects of running a SOC. If you like the topics in this podcast and would like to learn more about Blue Team leadership and management, check out the new MGT551: Building and Leading Security Operations Centers. This new course is designed for Security Team leaders looking to build, grow and operate a security operation center with peak efficiency. It’s a hands-on technical leadership course, that takes you through everything from scoping threat groups to use case creation, threat hunting, planning, SOC maturity and detection assessment and much much more.

    Check out the course syllabus, labs and a free demo at sansurl.com/551
    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    50 min
  • Josh Johnson: PowerShell and Defensive Automation for the Blue Team

    PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course "SEC586: Blue Team Operations - Defensive Powershell" giving you a masterful crash course in:

    - The importance of PowerShell
    - How PowerShell works, and how to set yourself up to use it
    - Blue team use cases for log analysis, incident response and more
    - How to stopping attackers from leveraging PowerShell
    - Some of the amazing automation and playbook opportunities you may be missing out on.

    Lots of actionable content for defenders here, don't miss in this episode!


    Our Guest: Josh Johnson
    Josh Johnson is a SANS Certified Instructor and course author of SEC586: Blue Team Operations: Defensive PowerShell. He has been working in the Information Security industry for over 10 years in varying roles with responsibilities ranging from penetration testing to incident response. Josh was Purple Teaming since before it had a name and used his offensive security skill set to find and pursue his true passion - Blue Team. Since then, he has been helping organizations of all sizes, and in varying industries from healthcare to retail to finance, improve their cyber defense capabilities.

    More About Josh

    Follow Josh: 
    Twitter | LinkedIn

    Sponsor's Note:

    Support for the Blueprint podcast comes from the SANS Institute.

    If you like the topics covered in this podcast and would like to learn more about blue team fundamentals such as host and network data collection, threat detection, alert triage, incident management, threat intelligence, and more, check out my new course SEC450: Blue Team Fundamentals.

    This course is designed to bring attendees the information that every SOC analyst and blue team member needs to know to hit the ground running, including 15 labs that get you hands on with tools for threat intel, SIEM, incident management, automation and much more, this course has everything you need to launch your blue team career.

    Check out the details at sansurl.com/450! Hope to see you in class!

    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn


    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    49 min
  • Chris Baker: Get A Handle On Your Vulnerabilities

    This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don't know where to start? Struggling to get system owners to take action? Trying to find ways to communicate the importance and status of your patching efforts?

    Check out this episode with vulnerability management expert Chris Baker for answer these to questions and much more!

    Our Guest: Chris Baker
    Chris Baker is an Information Security Leader with a deep background in information security including strategy development and operational excellence that has created highly efficient teams and delivered large impacts to the business value chain. He is a skilled risk management and information security professional with the versatility to lead large and diverse matrix teams and deep-dive into complex technical problems. A proven track record of collaborating effectively at all business levels while directing changes on a global, enterprise-wide scale.


    Follow Chris Baker
    @bakerc | LinkedIn


    Sponsor Note
    Support for the Blueprint podcast comes from the SANS Institute.

    Are you looking for the best in-depth training for your cyber defense team? Look no further than SANS blue team curriculum courses!

    Whether you focus on network or host data, Windows or Linux, or even specialize in open source intel, SIEM, SOC, or defensive architecture, the SANS Blue Team curriculum has the course for you. From long-time classics like SEC503 Network Intrusion Detection to the newer SEC530 Defensible Security Architecture and Engineering and SEC487 Open Source Intelligence Gathering - we've got you covered, no matter what your specialty.

    With an extensive archive of free webcasts on the SANS site, and free online demos available for most courses, you can easily check out the SANS blue team catalog and see which course is the best fit for you and your team.

    Check out the constantly growing list of available courses at sansurl.com/blueteamops
    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn




    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    40 min
  • Mick Douglas & Flynn Weeks: Simplifying your Logging Strategy with the What2Log Project

    A common question from many defenders is "Which logs are the most important?” In this episode, Mick Douglas and Flynn Weeks join us to describe their What2Log project, which aims to simplify this problem for all of us!

    Our Guests: Mick Douglas & Flynn Weeks
    Mick Douglas is the Managing Partner of InfoSec Innovations. He is a SANS certified instructor and is a member of the IANS faculty. In his spare time, he tries in vain to improve his photography skills and goes hiking looking for the perfect shot.

    Flynn is a senior Cybersecurity student and intern at InfoSec Innovations. Forensics, and in turn, logging, are passions of hers. In her spare time, she enjoys her time spent with pets and hiking.

    Follow Mick and Flynn
    Twitter:  Mick @bettersafetynet and Flynn @soundsofthetime


    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    47 min
  • Anton Chuvakin: The Current State and Future of Security Operations

    In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automation in the SOC and how Anton would setup a modern Security Operations Center for a Cloud native organization.

    Today's Guest: Anton Chuvakin
    Dr. Anton Chuvakin is a recognized security expert in the field of log management, SIEM and PCI DSS compliance. He is now involved with security solution strategy at Google Cloud, where he arrived via Chronicle Security (an Alphabet company) acquisition in July 2019. 

    He is an author of books "Security Warrior", "Logging and Log Management: The Authoritative Guide to Understanding the Concepts Surrounding Logging and Log Management" and ""PCI Compliance, Third Edition: Understand and Implement Effective PCI Data Security Standard Compliance"" (book website) and a contributor to "Know Your Enemy II", "Information Security Management Handbook" and other books. 

    Anton has published dozens of papers on log management, SIEM, correlation, security data analysis, PCI DSS, security management. His blog "Security Warrior" was one of the most popular in the industry. In addition, Anton teaches classes and presents at many security conferences across the world; he addressed audiences in United States, UK, Australia, Singapore, Spain, Russia and other countries. He works on emerging security standards and serves on advisory boards of several security start-ups.


    Follow Anton
    Twitter:  @anton_chuvakin
    LinkedIn: /in/chuvakin

    Check out the constantly growing list of available courses at sansurl.com/blueteamops
    Follow SANS Cyber Defense: Twitter | LinkedIn | YouTube
    Follow John Hubbard: Twitter | LinkedIn

    Contact, Courses, and More:

    For feedback, reviews, guest pitches, or to get in contact with me for any other reason, head to blueprintpodcast.live!

    Check out John's SOC Training Courses for SOC Analysts and Leaders:

    • SEC450: SOC Analyst Training - Applied Skills for Cyber Defense Operations
    • LDR551: Building and Leader Security Operations Centers

    Follow and Connect with John:  LinkedIn

    48 min

About Blueprint: Build the Best in Cyber Defense

From the publisher's feed

Are you a cyber defender looking to keep up on the newest tools, technology, and security concepts? Then BLUEPRINT is the podcast for you! Tune in to hear the latest in cyber defense and security…

More shows like Blueprint: Build the Best in Cyber Defense

Security Now (Audio) by TWiT

Security Now (Audio)

2,012 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

The Daily by The New York Times

The Daily

111,779 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,062 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners