Skip to content

Robert M. Lee

Goodbye Mike Assante, Thank you For Literally Everything

On July 5th, 2019 Mike Assante decided it was his time to leave this world and shuffle off this mortal coil. I say decided because as I would learn from Tim Conway, Mike didn’t want to die on July 4th because it would ruin the festivities of the holiday (he was deeply patriotic) and he…

Continue reading →

Homogeneous Infrastructure and Scalable Attacks

Industrial (ICS/IIoT/OT/variations of “not enterprise IT + physics”) infrastructure has benefited greatly in one form or another in having heterogeneous infrastructure. An electric transmission substation in one part of a single company is different than an electric substation elsewhere even in the same company; not only often in vendor choices but configuration, integration, implementation, and…

Continue reading →

Threat Hunting, TTPs, Indicators, and MITRE ATT&CK – Bingo

This blog is a continuation of a fantastic discussion with Richard Bejtlich. He responded to a question online, I blogged about it here and then he responded here and in response to another question I posed here. In this blog I’ll reply to his replies. The main point of this blog to me though is…

Continue reading →

Hunting vs. Incident Response vs. Just Doing Your Job

One of the things that motivates me to write is either being really pissed off or finding someone I really respect and having a different opinion. This blog is about the latter. Richard Bejtlich tweeted (oh the horror) that to him, hunting is just another form of detection. Now his real argument is of course…

Continue reading →

What It’s Like to Testify to the U.S. Senate

One of my SANS students challenged me recently that I haven’t posted on my blog in awhile; I realized I hadn’t and checked today and found that it’s been almost a year since my last post. So first of all, apologies on the delay. I’ve been busy (Dragos, Inc. has been expanding rapidly and we’re…

Continue reading →