Open in app

Sign In

Write

Sign In

John Lambert
John Lambert

491 Followers

Home

About

Nov 21, 2021

Defender’s Mindset

This is a collection of thoughts, quips, and quotes from tweets, blogs, and presentations over the years. If you find them helpful, drop me a note at @JohnLaTwC or on LI. Attackers seek to turn illegitimate access into legitimate access Your network often provides all the accesses and capabilities the attacker needs — because after all you need to…

Infosec

13 min read

Infosec

13 min read


Sep 16, 2020

The most beautiful equation in math

Want to see the most beautiful equation in math? I’ll show you. It starts with the Roots of Unity. What is unity? Unity just means the number 1. Let’s start with the square roots of 1. x² = 1 Or, what number multiplied by itself gives you a result of 1? …

Math

5 min read

The most beautiful equation in math
The most beautiful equation in math
Math

5 min read


Dec 29, 2019

Early Security Stories — Green Shellcode Contest

When I was working in the MSRC and SDL teams, I ran a series of contests. The goals were to encourage learning, foster a team culture around technical excellence, and have some fun. I wanted them to be accessible across program managers, vulnerability researchers, and engineers. Contest #1 The first one was…

Programming

4 min read

Early Security Stories — Green Shellcode Contest
Early Security Stories — Green Shellcode Contest
Programming

4 min read


Dec 28, 2019

Early Security Stories — ASLR

Story time. This one is about a feature in Windows called ASLR. It was 2005. We were working on Windows Vista. Most remember it as the release with the maligned User Account Control feature. …

Security

4 min read

Early Security Stories — ASLR
Early Security Stories — ASLR
Security

4 min read


Dec 28, 2019

Early Security Stories at Microsoft — the FSR

Everyone has moments that cement their decision to take their career in a certain direction. This is one of those. In 2004 my team was responsible for administering the Final Security Review on Microsoft products. The FSR was the final check that all security requirements had been met. I was…

Security

3 min read

Early Stories in the SDL at Microsoft
Early Stories in the SDL at Microsoft
Security

3 min read


Dec 8, 2019

The Githubification of InfoSec

Towards a more open, contributor friendly, vendor neutral model for accelerated learning in InfoSec By John Lambert, @JohnLaTwC, Distinguished Engineer, Microsoft Threat Intelligence Center Summary A community-based approach in infosec can speed learning for defenders. Attack knowledge curated in the MITRE ATT&CK™ framework, detection definitions expressed in Sigma rules, and repeatable…

Infosec

13 min read

The Githubification of InfoSec
The Githubification of InfoSec
Infosec

13 min read

John Lambert

John Lambert

491 Followers

Distinguished Engineer, Microsoft Threat Intelligence Center, @JohnLaTwC

Following
  • Florian Roth

    Florian Roth

  • Daniil Yugoslavskiy

    Daniil Yugoslavskiy

  • MSTIC

    MSTIC

  • Roberto Rodriguez

    Roberto Rodriguez

See all (9)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams