Simply Defensive

Hands-On Defense: Markus Schober on DFIR, Labs, and Building Better Blue Teamers


Listen Later

In this episode of Simply Defensive, Josh Mason and Wade Wells sit down with Markus Schober, founder of Blue Cape Security, to talk all things digital forensics, incident response (DFIR), and why hands-on training beats theory every time.


We dig into:
 🔹 The hidden value of building your own cyber range
 🔹 How IR pros train using real attacks (and why they need red team skills)
 🔹 Eric Zimmerman's forensics tools and practical lab setups
 🔹 Ransomware war stories from Fortune 100 response
 🔹 The role (and limitations) of AI in forensics
 🔹 How to break into DFIR as a practitioner — not just a paper tiger


Whether you’re building detections, teaching DFIR, or just figuring out where to start, this one’s for you.

👇 Timestamps https://www.bluecapesecurity.com/& Resources
 0:00 Intro & ThreatLocker sponsorship
 2:00 Markus' journey from responder to trainer
 5:00 What makes a good DFIR workshop?
 7:00 Building a cyber range that doesn’t suck
 10:00 Favorite open-source tools (hint: Zimmerman)
 14:00 Consulting vs. in-house IR
 19:00 APT10, ransomware, and real-world incidents
 24:00 Can AI replace forensic analysts?
 27:00 Where to find Markus' courses
 29:00 Parting wisdom for aspiring defenders

📚 Check out Blue Cape Security:
https://www.bluecapesecurity.com/
→ Hands-on IR & Forensics Labs
→ Certification (coming soon!)

🔗 Follow the hosts:
 Josh Mason: https://www.linkedin.com/in/joshuacmason/
Wade Wells: https://www.linkedin.com/in/wadingthrulogs/

💡 Brought to you by ThreatLocker – Secure your business with zero trust application control.

...more
View all episodesView all episodes
Download on the App Store

Simply DefensiveBy Simply Cyber Media Group

  • 5
  • 5
  • 5
  • 5
  • 5

5

2 ratings


More shows like Simply Defensive

View all
Hacked by Hacked

Hacked

184 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

7 Minute Security by Brian Johnson

7 Minute Security

69 Listeners

Smashing Security by Graham Cluley

Smashing Security

322 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,012 Listeners

Talkin' About [Infosec] News, Powered by Black Hills Information Security by Black Hills Information Security

Talkin' About [Infosec] News, Powered by Black Hills Information Security

94 Listeners

Hacker Valley Studio by Hacker Valley Media

Hacker Valley Studio

60 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

169 Listeners

The Hacker's Cache by Kyser Clark - Cybersecurity

The Hacker's Cache

2 Listeners