Threat Level: green Handler on Duty: Jan Kopriva

SANS ISC: ISC Handlers ISC Handlers

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Volunteer incident handlers donate their valuable time to analyze detects and anomalies, and post a daily diary of their analysis and thoughts on the Storm Center web site. Below you will find Handler details including personal pages, additional scripts or papers, or whatever the respective handler is interested in offering. All content is owned by the respective handler.

Interested in becoming a handler? A roadmap is available to learn how.

Current Handlers

Basil Alawi S.Taher

John Bambenek

Bambenek, John

John Bambenek is Vice-President of Security Research and Intelligence at ThreatSTOP where he leads the globally distributed research efforts for the company. In addition to his role there, he is a lecturer teaching cybersecurity courses at the University of Illinois at Urbana-Champaign in the Departments of Computer Science and Information Sciences and he is a handler with the SANS Internet Storm Center. He has spent 18 years in the industry helping research emerging threats and leading large-scale intelligence sharing communities to engage in targeted disruption of criminal activities online. He has developed a variety of techniques to conduct digital surveillance that is used to monitor domain generation algorithms and malware configurations which are used by thousands of organizations world-wide. In addition, he tracks financial transactions of various neonazi and supremacist individuals and organizations. He has spoken at conferences around the world, has published two books in addition to several book chapters and articles, and he once appears on the Daily Show with Jon Stewart.

Twitter:@bambenek

Recent Diaries:

View all diaries by this handler

Guy Bruneau

Jim Clausing


Upcoming Courses:

SANS San Antonio 2020, San Antonio
May 17, 2020 - May 22, 2020
Reverse-Engineering Malware: Malware Analysis Tools and Techniques

Instructor Page

Adrien de Beaupre

Brad Duncan

Russell Eubanks


Upcoming Courses:

SANS Cyber Defense Initiative 2019, Washington
December 10, 2019 - December 11, 2019
A Practical Introduction to Risk Assessment

SANS Cyber Defense Initiative 2019, Washington
December 10, 2019 - December 11, 2019
A Practical Introduction to Cyber Security Risk Management

SANS Security East 2020, New Orleans
February 01, 2020 - February 02, 2020
A Practical Introduction to Risk Assessment

Instructor Page

Scott Fendley

Lorna Hutcheson

Jan Kopriva

Kevin Liston

Kyle Lysek

Renato Marinho

Marinho, Renato

Renato Marinho is Chief Research Officer at Morphus Labs. His journey in the area began in 2001, when he created Nettion, one of the first firewalls to use the contemporary UTM (Unified Threat Management) concept. Experienced in cyber security, Marinho was internationally recognized in 2016 by his research that unveiled Mamba, the first full disk encryption ransomware. At Morphus Labs, he oversees research, innovation and development of new products. Master and PhD candidate in Applied Informatics, he is also professor at University of Fortaleza teaching Computer Forensics in the post-graduate course. He is also a speaker having presented at Ignite Cybersecurity Conference, BSides Delaware, BSides Vienna, WSKS Portugal and Brazilian CSIRTs Forum.

Twitter:@renato_marinho

Recent Diaries:

View all diaries by this handler

Russ McRee

Xavier Mertens

Mertens, Xavier

Xavier Mertens is a freelance cyber security consultant based in Belgium. Xavier started his own company (https://xavier.mertens.consulting) in 2013 to offer pentesting, incident handling and forensic services. He holds GIAC,GFCE, GCFA, GXPN & GREM certifications and is also CISSP and CISA. Xavier has a blog about security (https://blog.rootshell.be) and is co-organizer of the BruCON security conference (http://www.brucon.org).

Twitter:@xme

Recent Diaries:

View all diaries by this handler

Richard Porter

Marcus Sachs

Manuel Humberto Santander Pelaez

Santander Pelaez, Manuel Humberto

Mr. Santander Pelaez currently serves as the Chief Information Security Officer of Puntos Colombia S.A.S. . in Medellin,Colombia. His areas of interest are Intrusion Detection, Computer Forensics, Incident Response, SCADA Security, Network Design and cyberwarfare.

Twitter:@manuelsantander

Recent Diaries:

View all diaries by this handler

Kevin Shortt

Didier Stevens

Stevens, Didier

Didier Stevens (Microsoft MVP Consumer Security) holds many certifications from SANS, Microsoft, Cisco, ... He is a Senior Analyst (NVISO https://www.nviso.be). Didier started his own company in 2012 to provide IT security training services (http://DidierStevensLabs.com). You can find his open source security tools on his IT security related blog at https://blog.DidierStevens.com.

Twitter:@DidierStevens

Recent Diaries:

View all diaries by this handler

Johannes Ullrich

Ullrich, Johannes

Dr. Johannes Ullrich is the Dean of Research and a faculty member of the SANS Technology Institute. In November of 2000, Johannes started the DShield.org project, which he later integrated into the Internet Storm Center. His work with the Internet Storm Center has been widely recognized. In 2004, Network World named him one of the 50 most powerful people in the networking industry. Secure Computing Magazine named him in 2005 one of the Top 5 influential IT security thinkers. His research interests include IPv6, Network Traffic Analysis and Secure Software Development. Johannes is regularly invited to speak at conferences and has been interviewed by major publications, radio as well as TV stations. He is a member of the SANS Technology Institute's Faculty and Administration as well as Curriculum and Long Range Planning Committee. As chief research officer for the SANS Institute, Johannes is currently responsible for the GIAC Gold program. Prior to working for SANS, Johannes worked as a lead support engineer for a Web development company and as a research physicist. Johannes holds a PhD in Physics from SUNY Albany and is located in Jacksonville, Florida. More Details: http://www.linkedin.com/in/johannesullrich

Twitter:@johullrich

Click to  View Handler Page

Recent Diaries:

View all diaries by this handler

Upcoming Courses:

SANS San Francisco Spring 2020, San Francisco
March 16, 2020 - March 21, 2020
Defending Web Applications Security Essentials

SANS Amsterdam May 2020, Amsterdam
May 11, 2020 - May 16, 2020
Defending Web Applications Security Essentials

SANS Amsterdam May 2020, Amsterdam
May 17, 2020 - May 18, 2020
IPv6 Essentials

Instructor Page

Rob VandenBrink

Remco Verhoef

Rick Wanner

Tom Webb

Bojan Zdrnja


Upcoming Courses:

SANS Brussels February 2020, Brussels
February 17, 2020 - February 22, 2020
Web App Penetration Testing and Ethical Hacking

SANS Madrid March 2020, Madrid
March 23, 2020 - March 28, 2020
Web App Penetration Testing and Ethical Hacking

SANS 2020, Orlando
April 05, 2020 - April 10, 2020
Web App Penetration Testing and Ethical Hacking

Instructor Page