My Projects
I build tools, training, and guidance that help security practitioners sharpen their craft.
REMnux
I created REMnux to make it easier for people to examine malicious software. What started in 2010 as a small project has grown into the go-to environment for malware analysts worldwide. This free, open-source Linux toolkit bundles hundreds of community-built tools into a distro that just works, allowing analysts to focus on investigation rather than installation.
Incident responders and reverse engineers can get REMnux as a dedicated virtual machine, run it as a container, or add it to an existing compatible system. To connect the toolkit to AI workflows, I released the REMnux MCP server, which lets AI agents use REMnux tools to analyze malware.
Cybersecurity Training
I created the Reverse-Engineering Malware course at SANS Institute to help others enter this field. Many of today's incident responders got their start analyzing malware in this class. Together with Ryan Chapman, I'm updating the course for the age of AI. Students will learn to amplify their capabilities using AI agents, along with the foundational techniques every malware analyst needs.
I'm developing a new SANS course, LDR550: Leading Agentic Security Teams. Security leaders will learn to redesign their security programs with AI to expand their teams' capacity and speed up decisions. You can get notified when it launches.
I'm also co-authoring a new course on the emerging VulnOps practice. Security professionals will learn to handle vulnerabilities as a continuous operation to escape the vulnerability management hamster wheel. This includes basing each fix on business context, automating low-risk patches, and keeping people in charge of risky changes.
I also realized that technical skills aren't enough—security professionals need to communicate effectively to be heard. To fix this gap, I created Cybersecurity Writing: Hack the Reader. This SANS course teaches security professionals how to create content that drives action. I wrote about the philosophy behind it when I released the course.
AI Defense Matrix
I co-authored the AI Defense Matrix with Sounil Yu as the "security for AI" companion to his Cyber Defense Matrix. It helps security leaders find gaps, assign ownership, and select controls to defend AI systems, and it helps vendors explain their value and plan product strategy.
Existing AI security frameworks each cover one slice of the work, such as naming the AI components to protect or ranking application risks. Sounil and I combined those slices into a single grid of eight AI asset classes mapped across the six NIST CSF functions. I explained the thinking when we introduced the matrix.
Cyber Company Profiles
I also created Cyber Company Profiles, which independently analyzes the market positions and product strategies of hundreds of cybersecurity companies. The profiles answer the questions I kept asking as a security buyer and product leader, such as where a vendor is taking its portfolio and whether a startup will still be around in a few years.
Cyber Company Profiles puts every company through the same questions and the same scoring scales, so scores stay comparable across vendors. Ask a generic AI assistant those questions and the answers change with each run. AI produces each profile autonomously from cited public sources, and every claim links to the source behind it. I wrote about the approach when I launched the project.
Templates and Frameworks
I've published a set of templates that give security teams a running start on reports and briefings. The set includes report templates for incident response, cyber threat intelligence, security assessments, and malware analysis, plus briefing templates for updating executives. You can adapt them to your organization instead of starting from a blank page.
I created the Security Autonomy Matrix to help security leaders decide how much authority their AI agents get. It's a table with one row per security workflow, recording five decisions for leaders to make about each one. With those decisions in one place, leaders can enforce them through their tooling. They can widen an agent's autonomy after a good track record and take it away after repeated mistakes.
I've also published frameworks for product strategy decisions. My Security Product Creation Framework organizes the questions to answer when building a security product, and I've shown how to score a vendor's defensibility as AI drives down the cost of building software.
Community Presentations
I speak at industry events to share what I've learned about cybersecurity strategy and tactics. Here are some of the talks with videos available for you to view:
- How to Keep Your Cool and Write Powerful Incident Response Reports (RSA Conference): What frameworks and checklists are available to help professionals rein in the chaos of incident response and deliver useful and actionable reports?
- Whoa, You've Been the CISO for 3 Years—Now What? (RSA Conference): What opportunities are available to CISOs who decide to stay in their roles after making an initial impact? Co-presented with Yael Nagler.
- Writing Effective Threat Reports (SANS Summit): How can security professionals create effective threat reports to inform a diverse set of stakeholders?
- How Security and Privacy Teams Break Barriers Together (RSA Conference): How can security and data privacy teams collaborate to strengthen their respective programs? Co-presented with Edy Glozman.
This Blog
I've been writing on this site since 2010 as a way to think out loud and share resources with the community. I've explored a variety of topics, including malware analysis, security leadership, artificial intelligence, and more. I've also published cheat sheets that condense many security and IT concepts into actionable references.
Writing is how I make sense of the industry. I hope you find something in the collection that helps you do the same. If you want to receive my blog posts by email, subscribe to my newsletter. And if you want to wander around, read a random article or search for something specific.