Skip to content
View jshlbrd's full-sized avatar
Block or Report

Block or report jshlbrd

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jshlbrd/README.md

Josh Liburdi

Reach me on LinkedIn if you want to chat!

πŸ“‘ Open-Source Software

πŸ’‘ Substation

  • Cloud-native, event-driven data pipeline toolkit designed for security and observability teams
  • Creator and lead developer since early 2021

πŸ“‚ Strelka

  • Enterprise scale static file analysis system written in Python & Go
  • Creator and lead developer from early 2017 to late 2019
  • Used by Sublime Security, Security Onion, and large organizations like Target

🌐 Zeek

  • Shares challenges and best practices for building large scale data processing systems using the AWS serverless stack
  • Presented at fwd:cloudsec in mid 2023
  • Describes how low quality data contributes to inefficient threat hunting operations
  • Presented at the SANS Threat Hunting Summit in late 2021
  • Advocates for adding detection-oriented file analysis systems to the modern threat detection tech stack
  • Presented at BSides San Francisco in early 2019
  • Provides an overview to network-based threat hunting, including tools and techniques
  • Presented at BSides New York City in early 2016

πŸ“ Writing

  • In-depth overview of building an automated security alert management system
  • Shared on Medium in early 2023
  • Explains how to organize threat hunts that are structured and task-driven
  • Shared on Medium in early 2020
  • Details how to programmatically use heatmaps to identify malicious PowerShell across multiple Windows systems
  • Shared on Medium in early 2017

Popular repositories

  1. detection-engineering-pocket-guide detection-engineering-pocket-guide Public

    pocket guide for core detection engineering concepts

    26 2

  2. threat-hunting-pocket-guide threat-hunting-pocket-guide Public

    pocket guide for core threat hunting concepts

    21 4

  3. laikaboss-modules laikaboss-modules Public

    Python 17 2

  4. bro-scripts bro-scripts Public

    various bro scripts

    Bro 8 5

  5. bro-plugins bro-plugins Public

    A repo for Bro plugins.

    JavaScript 6 4

  6. python-drawer python-drawer Public

    Python 4