
Chris Daywalt is a security freelancer in the defensive space who spends much of his day doing and teaching Digital Forensics and Incident Response (DFIR).

Courses

Careers In Cybersecurity

Lateral Movement: Remote Desktop Protocol (RDP)

Valid Accounts: Local Accounts

Protocol Tunneling

Exfiltration Over Alternative Protocol: Asymmetric Encrypted Non-C2 Protocol

Lateral Movement: Windows Remote Management

Application Layer Protocol for C2 and Exfil to Cloud

Unsecured Credentials and Domain Accounts

Disable Windows Event Log and Timestomp

Compromise Software Supply Chain

Ransomware with Recovery Disruption

Using LOLbins for Tool Downloads
After too many years of security operations work, Chris Daywalt tries to turn his phone off at 5:00 pm EST. While there are a bunch of training classes and education somewhere on his resume (including CTT+ and Cellebrite certifications), much of what he has to teach was learned at the school of hard knocks, often at the expense of his previous clients. He wants to help you spend more time detecting and denying adversaries and less time banging your head against your keyboard. He dips his blueberry donuts in orange juice.
Chris’ 19-year career includes work for organizations of all sizes, both government and private sector, and is distributed roughly like so: