“The Father of Eight” at the WTC site on 3 Sept 2002.

Never forget.

Interesting story I’ve never shared before… like everyone that day, I was in a state of shock. In my lifetime it was the first time we felt under attack. I remember it like it was yesterday, where I was in Symphonic Winds with Mr. Albinder. We were playing “Where Never Lark or Eagle Flew”, a somewhat eerie song for that moment. We continued to play the song, over and over and over, even after the Principal made the announcements on the loud-speaker.

Going home that day, I became even more hooked on news (I was a huge CNN…


Incident Response and Containment

Anyone who does Incident Response (IR), or any Digital Forensics Incident Response (DFIR) process knows that collecting Indicators of Compromise (IOC) is only half the story. Eventually, you’ll need to recover the environment, which inherently means you best have confidence in the IOCs and have a plan to evict the adversary.

Before we go into detail on just how to do that, it is paramount to talk about containment. Anytime a recovery team comes in and takes intel from the IR team, a plan must be executed while being sensitive to the control-plane an adversary should have after a step…

Andrew Harris

Sr Director, Public Sector Technology Strategy at CrowdStrike. Ex-MSFT, Department of Defense civilian. Advocate of human rights, privacy, decency.

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store