BSides Chicago

I had the privilege of speaking at BSides Chicago 2013 on "Advanced Threat Detection and Forensics via NetFlow and IPFIX" last week. I had a great time (arguably too great) listening to the talks, networking and rapping with the participants that stuck with me for 50 minutes. I wanted to thank @rogueclown for the great support and encouragement. Thanks to @kylemaxwell for his wise advice (which I foolishly ignored) and great conversation. Thanks to @securitymoey and @elizmmartin for coordinating such a fun event.

For those that may have missed the talk you can pull down the presentation here.

It was a great time, great people and I look forward to the next meet up.

About the Author

Charles Herring

Charles Herring

Co-founder & Chairman, WitFoo

I started WitFoo in 2016 to make information and operations shareable across the craft of cybersecurity — between companies, law enforcement, national security and insurers, who mostly cannot see what each other sees. Before that I was at Lancope and Cisco, and I began in 2002 as Network Security Officer for the Naval Postgraduate School.

I lead research and development on a platform that ingests trillions of messages a day across hundreds of clusters. It is sold as Conductor, Reporter and Analytics, licensed flat per appliance with unlimited data — because a team charged by the gigabyte ends up making coverage decisions on a spreadsheet, months before the incident that needed the logs they dropped.

Everything here is mine, not the company's, and it wanders. Corrections are genuinely welcome — I would rather be right than consistent.

A note on how this was written: I use artificial intelligence tools to help me research, check facts, and edit these posts. The ideas, the arguments, and any mistakes are mine. I read the sources, I check the claims, and I take full responsibility for what I publish here. The views are my own and the writing is my intellectual property.