So...I'm not Bilbo Baggins...obviously (shut up with the short jokes), but I have recently embarked on a very welcome, albeit unexpected journey. Let me explain...
Sometimes, leaving is more about moving towards something new rather than moving away from where you currently are. Such is the case with my departure from SpiderLabs. I have truly enjoyed the almost six years I spent there as an Investigator and Director, but when this new opportunity found me, like Bilbo and his beloved ring, I could not resist.
In my first conversation with my new boss, Jim Kent, I have to admit, I was not all that excited about going to work at a software company. Having worked in the field for so many years, like most investigators, I have come to loathe commercial forensic tools. I have seen them as a necessary evil, something we had to have for RFPs or for courtroom testimony, but not something we actually worked cases with. Along with the likes of Corey Altheide, Harlan Carvey, Rob Lee, and Hal Pomerantz, I have beat the drum of using Open Source forensics tool, because...and let's all say this together, "This is NO SUCH THING as COURT APPROVED"! It's all about the way you interpret the 1s and 0s of an investigation and not the tool that you use! YOU are the investigator, YOU are the one that testifies, not the tool. Anyways, I was not expecting this conversation to go anywhere, but I listened to what Jim had to say. It's a good thing too...because what he said make the conversation take a 180, and head off in a totally unexpected direction.
Jim: So, I have been reading up on this Sniper Forensics methodology of yours, and I have to say, it's spot on.
Me: Thank you.
Jim: What would you say if I told you that our tool, Nuix Investigator is Sniper Forensics come to life?
Me: (stunned) Say that again...
Jim: Our tool suite at Nuix is very much the embodiment of your Sniper Forensics methodology. We'd love for you to come be a part of our team and help us take our tool to the next level.
From that point in the conversation, my journey began, and as I stated initially, it was less about leaving SpiderLabs, and more so about joining Nuix. I could not be more excited to be part of this team, and I am blown away by what the Nuix engine can do, that it really, no kidding incorporates Sniper Forensics, and that I get to be a part of making it everything I have always wished a forensic tool would be! In my opinion, this is the intelligence multiplier we have all been waiting for. The hunt is about to change.
The next six months are going to be a whirlwind. I have so many ideas about what to do, and how to do it that my fingers and keyboard are having a hard time keeping up with my brain. But, I don't want to be so naive as to think that my ideas are the best and or only ones. So, I want to turn to YOU...the DFIR community for assistance. In the coming weeks, I am going to be taking in feedback from you...as many of you that will email me at chris.pogue@nuix.com - AND, I am also going to be making trips to see some of you - Chicago, San Francisco, Sarasota, DC, New York (HOPE), and Vegas (Blackhat / DEFCON) - to get YOUR feedback (if you are in or around those areas, drinks are on me)! Tell me what you have always wanted to see in a commercial forensic tool suite? What have you wanted it to feel like? What features and functionality have you always wished for? And please...DON'T HOLD BACK...the sky is the limit. You shoot for the moon...my job is to figure out how to make it happen.
We are going to turn the DFIR world upside down, and bring to market the most effective, most efficient, fastest, best, Sniper Forensic-y tool on the planet! I am looking forward to hearing from, or seeing you!
In the immortal words of Ton-Loc..."Let's do it"!
*** In the past I have said, "Happy Hunting", but...since the new gig puts me in a bit of a different position...let's go with this...
"Changing the hunt!" ***
This Blog is dedicated Digital Forensics and Incident Response, tools, techniques, policies, and procedures.
Showing posts sorted by relevance for query sniper forensics. Sort by date Show all posts
Showing posts sorted by relevance for query sniper forensics. Sort by date Show all posts
Saturday, June 7, 2014
Sunday, October 24, 2010
SecTor 2010 - Debuting SF2

I will be debuting the second version of Sniper Forensics, titled, "Target Acquisition" at SecTor in Toronto, Ontario, Canada on October 27th. It's a great conference and I couldn't be more excited!
Here are some quotes about what others are saying about SF2!
“As environments continue to grow in size and complexity, incident response teams entrenched in the “image everything” methodology will find themselves not able to understand the situation as fast as the threat is evolving within a target environment. Adopting the Sniper Forensics Methodology, will decrease the cost of the investigations while providing results many times faster over traditional approaches when applied to modern environments.”
- Nicholas Percoco
Senior Vice President, Trustwave SpiderLabs
=============================
“If you have a specific goal, you are much more likely to achieve it. Knowing what you want out of an investigation, before you start, will help you know when you're finished.”
- Jesse Kornblum
Computer Forensics Research Guru, Kyrus Technology
=============================
"Using F-Response as part of the "Sniper Forensics" model is the perfect logical extension of our original mission. Get answers, not just information."
- Matt Shannon
Founder, F-Response
=============================
“'Sniper Forensics: Target Acquisition' walks up to an analyst and slaps him right in the face! Here are targeted tools and techniques, straight from successful field ops, that every analyst needs to know! Once you've defined your target, go grab the data you need, and optimize your time and resources to get the job done!”
- Harlan Carvey
Vice President of Advanced Technical Projects, Terremark Worldwide
Author of “Windows Forensic Analysis 2nd Edition”
Author of the Blog, “WindowsIR.blogspot.com”
Sunday, March 7, 2010
Sniper Forensics Accepted at CFS

I found out this week that my presentation, "Sniper Forensics" has been accepted at this year's Computer Forensics Show, in New York.
I gave the first version of this talk last year at SecTor in Toronto and it met with some pretty good reviews. So, I submitted to a few of the larger forensics conferences here in the US, and CFS is the first to pick it up.
Also, there is a great article covering my talk by Lynn Greiner in the Winter 2009 article of "Networker". You can download the article from (just cut and paste the entire link into your browser and the PDF will download):
http://www.google.com/url?sa=X&q=http://portal.acm.org/ft_gateway.
cfm%3Fid%3D1655740%26type%3Dpdf%26coll%3DGUIDE%26dl%3DGUIDE%26CFID%3D1515151
5%26CFTOKEN%3D6184618&ct=ga&cd=f8ZyPcEyIdQ&usg=AFQjCNFOH4C8yz7y6cTahaMvNAFNK
vgQeQ
The talk covers the basic premise that computer forensics has more to do with methodology, and taking a targeted approach to an investigation than with what tools you use. It's a pretty good preso, and after I have given it this year at the US cons, I will post it here for anyone to download.
Wednesday, January 19, 2011
SpiderLabs Anterior - Sniper Forensics
Sniper Forensics: Part 1
I have recently blogged about the Sniper Forensics methodology at the SpiderLabs Anterior blog...which is THE official blog of the Trustwave SpiderLabs. Check it out!
I have recently blogged about the Sniper Forensics methodology at the SpiderLabs Anterior blog...which is THE official blog of the Trustwave SpiderLabs. Check it out!
Tuesday, October 12, 2010
Call for quotes
I will be delivering Sniper Forensics v2.0 - Target Acquisition at SecTor this month in Toronto, Canada. To add some down home flavor to the preso, I would like to issue a "call for quotes" to anyone who uses the Sniper Forensics methodology. I will use between 5 and 10 quotes depending on your responses...so...I may not use any! But please, if you have heard my talk or read about it, and use the SF methodology, please let me know what you think!
Thanks!
Thanks!
Tuesday, November 16, 2010
Sniper Forensics Videos!
The kind folks at SecTor just posted the videos from SecTor 2010! ALSO, there is a link there for the videos from 2009.
If you have not had a chance to see either of the Sniper Forensics talks, now is your chance to download the videos or the slide decks!
If you have not had a chance to see either of the Sniper Forensics talks, now is your chance to download the videos or the slide decks!
Friday, January 21, 2011
Sniper Forensics Part 2 Posted
I have posted part two of Sniper Forensics to the SpiderLabs Anterior blog.
Check it out! Great stuff! (or at least I think so)
Check it out! Great stuff! (or at least I think so)
Thursday, May 5, 2011
Thursday, June 3, 2010
Wednesday, May 9, 2012
Repins Forensics
OK...so this my interpretation of, "Bizarro" forensics, which sadly, REALLY still happens. I was recently reminded of not only this, but of just how big the forensic world is, how many investigators there are, and how far we still have to go.
Sniper Forensics (SF) is the targeted approach to conducting forensic investigations. It helps the investigator to use logic to guide his/her investigation to find answers, not just gather data. Now, I am not going to rehash SF, but I just wanted to mention it briefly for the purpose of comparison.
The opposite of SF would be to illogically and haphazardly gather data that may or may not be relevant to the case (who cares if it makes sense, just pull the plug and gather everything). You would form your theory of what you or your client thinks happened, and force all of your evidence into that theory. You would ignore any evidence that was contrary to that theory, and think anyone who actually questioned what you did or the way you did it, is just plain wrong.
When asked questions like, "Did you perform Registry Analysis, Memory Analysis, or Pcap Analysis" you say..."Yes...I found nothing of evidentiary value". Then I may ask, "OK, what kind of analysis did you perform? What were you looking for?" You would answer something like, "I did analysis...I didn't find anything".
You would then defend your lack of findings by stating that the evidence was not clear what took place. While you can never be 100% certain of what happened, based on my analysis and experience, there was no breach that is evident.
This may sound ridiculous, but it is sadly true. There are still investigators that think like this, and cases that work like this. Do you know of any? I would love to hear your stories of Bizarro Foreniscs! Email them to me and I will create a blog series with the best of the worst. Should be entertaining!
I am working on my example now. It's pretty bad...and yes...we found the breach and it was ugly!
Sniper Forensics (SF) is the targeted approach to conducting forensic investigations. It helps the investigator to use logic to guide his/her investigation to find answers, not just gather data. Now, I am not going to rehash SF, but I just wanted to mention it briefly for the purpose of comparison.
The opposite of SF would be to illogically and haphazardly gather data that may or may not be relevant to the case (who cares if it makes sense, just pull the plug and gather everything). You would form your theory of what you or your client thinks happened, and force all of your evidence into that theory. You would ignore any evidence that was contrary to that theory, and think anyone who actually questioned what you did or the way you did it, is just plain wrong.
When asked questions like, "Did you perform Registry Analysis, Memory Analysis, or Pcap Analysis" you say..."Yes...I found nothing of evidentiary value". Then I may ask, "OK, what kind of analysis did you perform? What were you looking for?" You would answer something like, "I did analysis...I didn't find anything".
You would then defend your lack of findings by stating that the evidence was not clear what took place. While you can never be 100% certain of what happened, based on my analysis and experience, there was no breach that is evident.
This may sound ridiculous, but it is sadly true. There are still investigators that think like this, and cases that work like this. Do you know of any? I would love to hear your stories of Bizarro Foreniscs! Email them to me and I will create a blog series with the best of the worst. Should be entertaining!
I am working on my example now. It's pretty bad...and yes...we found the breach and it was ugly!
Friday, December 21, 2012
How Do I Get There From Here - Part 2
So, I have had more folks ask me about a career in Incident Response and Computer Forensics lately, so I thought I would expound a bit on my original post, How Do I Get There From Here.
I think it's worth mentioning again, that the thing that will propel you in your career, regardless of what that may be, is sheer desire. Getting up everyday, and thinking that you are not going to work because you have to, but rather that you get to go work doing something you love, makes a huge difference. I cannot stress that enough...to be a really good investigator, there is no other way.
Something else that I have recently discovered (thanks to some great Detectives) is a great skill to have is the ability to spot patterns and anomalies. So much of what we do in solving cases begins with finding something that just doesn't look right. You don't have to know exactly what it is, but you know something is just off will lead you down the path of taking a deep dive into that, "thing" which will either prove or disprove your hypothesis. Then, Sniper Forensics baby, you either use that finding to guide your investigation further, or you step back, formulate a new hypotheses, and drive on. But that initial "hrm...what are you" moment, is something you should experience throughout your investigations.
I spoke about this at a conference once, and I was asked, "How do I learn how to spot anomalies " Which is a valid questions...to which I answered, "By knowing what "normal" looks like". You need to put in the chair time. You need to know what processes should be running, from where, what is common, why - basically what makes a normal system look normal. I was a sysadmin for many years before I ever moved into security, which helped me tremendously once I moved into the DFIR world. If you don't have that background, then virtualization is a great thing. Fire up some VMs of different operating systems and just look at it. It sounds boring...but you know...wax on wax off...
Spotting patterns is a bit different. It requires you to be able to look at data elements and find similarities in them that could be anomalous. The best example I can think of is reviewing web logs for IOCs of SQL Injection or RFI. If you have ever seen these attacks in logs before, you know what I am referring to. You can actually see patterns of the attacker walking the database structure. If he's using an automated tool to do this, you can spot it a mile away - if you scroll through the logs, it looks like a series of shark fins. The same holds true for RFI attacks...you can spot the pattern of the attacker trying to get the system to upload his file. This is also the case for several different kids of attacks...they have visible patterns that after you put in some chair time, you can spot. Again, even if you don't know exactly what you're looking at just that it's unique when compared to it surroundings.
OK Chris...that's all well and good in theory, but that does not help me find a DFIR job. Do you have any recommendations that will help me actually get in the door? Great question...and Yes...yes I do.
OK...Bit of history...when I was a sysadmin at American Express in Phoenix, I used to admin both Windows and *nix servers (Solaris, AIX, and Linux). It was pretty cool, but kind of boring as it didn't present anything in the way of challenges (at least for me...no offence to Sysadmins...that's my roots!). So, I started looking into this whole security thing (this was about 2001). Pentest looked kewl to me. I knew how to make stuff work...let's see if I can learn how to break into those same systems. Since I didn't actually have a security job, I couldn't actually DO anything security related at work. So, I bought a copy of VMware, and started playing with tools. What was Metasploit and what did it do? What is ARP spoofing...can I do that at home? Basic research in my home lab. So, when I finally found an opening and got an interview, I was able to tell the hiring manager that all I have is what I found in the open source community, and my home lab, but I practice and research at home. I read books, blogs, and whitepapers trying to get as much knowledge as I could without actually doing the job. Well, I got the job for that very reason.
All of that to say...do that. If you want a job in DFIR and you are not currently working in DFIR, then research in your home lab. Take images of your systems, your ipod, your buddies laptops...whatever and start to play with the tools of the trade. Learn how to mount images, create timelines, parse data on the command line, learn how to use grep, gawk, and cut, use RegRipper to inspect registry hives...etc. Knowing which tool to use, when and why is critical! Remember, I rarely ever use commercial forensics tools. You can conduct comprehensive investigations without ever spending a dime!
So, if when somebody interviews you, and you tell them...I don't do this for a living but I want to and here is what I am doing to prepare myself for that, that should speak volumes about the type of employee you would be. I know for me, you would certainly shoot to the top of my list.
I hope that helps clarify things a bit for those of you that are seeking careers in DFIR. If there is something you would like me to expand on, please let me know! Or, if there is something I mentioned that you would like me to dig deeper into, please let me know. I am more than happy to help! After all, I may be interviewing you someday. It would be great to hear that you read my blog posts and so you did X.
Best of luck to you!
I think it's worth mentioning again, that the thing that will propel you in your career, regardless of what that may be, is sheer desire. Getting up everyday, and thinking that you are not going to work because you have to, but rather that you get to go work doing something you love, makes a huge difference. I cannot stress that enough...to be a really good investigator, there is no other way.
Something else that I have recently discovered (thanks to some great Detectives) is a great skill to have is the ability to spot patterns and anomalies. So much of what we do in solving cases begins with finding something that just doesn't look right. You don't have to know exactly what it is, but you know something is just off will lead you down the path of taking a deep dive into that, "thing" which will either prove or disprove your hypothesis. Then, Sniper Forensics baby, you either use that finding to guide your investigation further, or you step back, formulate a new hypotheses, and drive on. But that initial "hrm...what are you" moment, is something you should experience throughout your investigations.
I spoke about this at a conference once, and I was asked, "How do I learn how to spot anomalies " Which is a valid questions...to which I answered, "By knowing what "normal" looks like". You need to put in the chair time. You need to know what processes should be running, from where, what is common, why - basically what makes a normal system look normal. I was a sysadmin for many years before I ever moved into security, which helped me tremendously once I moved into the DFIR world. If you don't have that background, then virtualization is a great thing. Fire up some VMs of different operating systems and just look at it. It sounds boring...but you know...wax on wax off...
Spotting patterns is a bit different. It requires you to be able to look at data elements and find similarities in them that could be anomalous. The best example I can think of is reviewing web logs for IOCs of SQL Injection or RFI. If you have ever seen these attacks in logs before, you know what I am referring to. You can actually see patterns of the attacker walking the database structure. If he's using an automated tool to do this, you can spot it a mile away - if you scroll through the logs, it looks like a series of shark fins. The same holds true for RFI attacks...you can spot the pattern of the attacker trying to get the system to upload his file. This is also the case for several different kids of attacks...they have visible patterns that after you put in some chair time, you can spot. Again, even if you don't know exactly what you're looking at just that it's unique when compared to it surroundings.
OK Chris...that's all well and good in theory, but that does not help me find a DFIR job. Do you have any recommendations that will help me actually get in the door? Great question...and Yes...yes I do.
OK...Bit of history...when I was a sysadmin at American Express in Phoenix, I used to admin both Windows and *nix servers (Solaris, AIX, and Linux). It was pretty cool, but kind of boring as it didn't present anything in the way of challenges (at least for me...no offence to Sysadmins...that's my roots!). So, I started looking into this whole security thing (this was about 2001). Pentest looked kewl to me. I knew how to make stuff work...let's see if I can learn how to break into those same systems. Since I didn't actually have a security job, I couldn't actually DO anything security related at work. So, I bought a copy of VMware, and started playing with tools. What was Metasploit and what did it do? What is ARP spoofing...can I do that at home? Basic research in my home lab. So, when I finally found an opening and got an interview, I was able to tell the hiring manager that all I have is what I found in the open source community, and my home lab, but I practice and research at home. I read books, blogs, and whitepapers trying to get as much knowledge as I could without actually doing the job. Well, I got the job for that very reason.
All of that to say...do that. If you want a job in DFIR and you are not currently working in DFIR, then research in your home lab. Take images of your systems, your ipod, your buddies laptops...whatever and start to play with the tools of the trade. Learn how to mount images, create timelines, parse data on the command line, learn how to use grep, gawk, and cut, use RegRipper to inspect registry hives...etc. Knowing which tool to use, when and why is critical! Remember, I rarely ever use commercial forensics tools. You can conduct comprehensive investigations without ever spending a dime!
So, if when somebody interviews you, and you tell them...I don't do this for a living but I want to and here is what I am doing to prepare myself for that, that should speak volumes about the type of employee you would be. I know for me, you would certainly shoot to the top of my list.
I hope that helps clarify things a bit for those of you that are seeking careers in DFIR. If there is something you would like me to expand on, please let me know! Or, if there is something I mentioned that you would like me to dig deeper into, please let me know. I am more than happy to help! After all, I may be interviewing you someday. It would be great to hear that you read my blog posts and so you did X.
Best of luck to you!
Friday, August 12, 2011
Investigation Plans
I presented Sniper Forensics at two different conferences this past week and I am honestly, still alarmed by the number of investigators that still don't create an investigation plan at the beginning of a case. So, to sound like a broken record...If you are currently working cases, and NOT creating an investigation plan..START.
Here is what I do...
First, I open Case Notes and open my custom tab that I have labeled, "Investigation Plan".
Second, I sit back and think about what it is that I have been asked to do. This will obviously change from case to case, agency to agency, and person to person, but the general goal should be the same. You have been asked to identify something for some reason. You are not conducting the investigation for the sake of the investigation itself.
Once I have my overall goal, I write it down in my Case Notes..."I have been asked to confirm blah.
Third, I brainstorm on the "stuff" I will likely need to accomplish my goal. Will I need logs, will I need to interview customer (victim) employees, will I need timeline data, registry data...whatever.
Fourth, I use my tab that I have labeled, "Questions", and I ask myself questions that based on the data I just brainstormed, should help me to accomplish my overall goal. Throughout the investigation, I answer my questions. These answers will either terminate my line of thinking in that area and provide me with a new theory, or support my theory, enabling me to continue down the same path.
Following this brief but very useful exercise will give clarity to my investigation as well as provide success indicators so that I know I have found what I am looking for! Without a clear idea of what you have been asked to do, an investigator can easily become lost in the, "Fog of Forensics" and his case can grind to a stand still.
If you are using Investigation Plans...Good on you! If you are not...start...I promise you will see significant and immediate benefits!
Now...that pretty much concludes
Here is what I do...
First, I open Case Notes and open my custom tab that I have labeled, "Investigation Plan".
Second, I sit back and think about what it is that I have been asked to do. This will obviously change from case to case, agency to agency, and person to person, but the general goal should be the same. You have been asked to identify something for some reason. You are not conducting the investigation for the sake of the investigation itself.
Once I have my overall goal, I write it down in my Case Notes..."I have been asked to confirm blah.
Third, I brainstorm on the "stuff" I will likely need to accomplish my goal. Will I need logs, will I need to interview customer (victim) employees, will I need timeline data, registry data...whatever.
Fourth, I use my tab that I have labeled, "Questions", and I ask myself questions that based on the data I just brainstormed, should help me to accomplish my overall goal. Throughout the investigation, I answer my questions. These answers will either terminate my line of thinking in that area and provide me with a new theory, or support my theory, enabling me to continue down the same path.
Following this brief but very useful exercise will give clarity to my investigation as well as provide success indicators so that I know I have found what I am looking for! Without a clear idea of what you have been asked to do, an investigator can easily become lost in the, "Fog of Forensics" and his case can grind to a stand still.
If you are using Investigation Plans...Good on you! If you are not...start...I promise you will see significant and immediate benefits!
Now...that pretty much concludes
Thursday, February 23, 2012
Thursday, April 8, 2010
The Next HOPE Conference

Sniper Forensics was just picked up by The Next HOPE (Hackers On Planet Earth) conference in New York City from July 16 - 18. Sweet!
Thursday, May 10, 2012
SecTor 2012 First Round!
Sniper Forensics: Reloaded has been accepted in the first round of CFP selections at SecTor 2012!
This is one of the best security conferences of the year! If you have never been, I HIGHLY recommend it.
This is one of the best security conferences of the year! If you have never been, I HIGHLY recommend it.
Thursday, March 10, 2011
SANS What Works Summit 2011
I was just informed by Rob Lee that Sniper Forensics 2.0: Target Acquisition has been selected for this year's SANS What Works in Incident Response Summit in Austin Texas! Sweet! See you there!
Tuesday, November 15, 2011
Tuesday, August 16, 2011
CyberSpeak Interview
I just finished an interview with Ovie Carroll on CyberSpeak! It should be posted in about two weeks! Give it a listen!
Talked about Sniper Forensics and how it rocks the hizzie!
Monday, June 6, 2011
Wednesday, November 16, 2011
Subscribe to:
Posts (Atom)





