Tuesday, January 26, 2016

Sample GDWP - ISE 5700

GDWP Assignment

Dear XXX

Your ISE5700 assignment is below. Please do not discuss the details of the assignment with other students for at least 30 days, but if you have questions or concerns, feel free to contact Stephen Northcutt, (Stephen@sans.edu) directly.


If you do call with questions, after the call is complete, please have a member of the team create a Memo to Record of what was discussed and what was decided and email to all involved parties with your final project submission.

===


There are THREE parts to your total project submission:

A. Technical report counts as 50% of GDWP score.
Your paper should include a CIO level executive summary to introduce your recommendations. The technical report should include: executive summary, the sub-assignments, and any appendices, and/or references. The rubric for grading the paper is shown below in the assignment. Max length fifteen (15) pages, typed single spaced, double-spaced between paragraphs. Hard and soft copies expected, (hard copy to the onsite STI representative), email soft copy to Stephen Northcutt (Stephen@sans.edu) , Toby Gouker (tgouker@sans.edu), Chris Crowley (chris@montance.com) with copies to registrar@sans.edu. Submitted project emails must be sent before the live presentation.


B. "Back-of-the-envelope project plan" counts as 10% of the score.
Plan should include the relevant tasks, milestones, resources assigned to
the tasks and schedule. This is the first thing you do after receiving your
project assignment. Email to Stephen Northcutt Stephen Northcutt
(Stephen@sans.edu) , Toby Gouker (tgouker@sans.edu), Chris Crowley (chris@montance.com) with copy to
registrar@sans.edu as soon as reasonable. Text only is fine. If you create a
diagram using computer tools, send as a JPEG or similar. If hand- done, scan
it or take a legible picture with a smartphone. Make sure to record the
amount of time to develop the plan and treat completion of the plan as a
milestone for the completed submission. Can you change your plan if you run into trouble? Of course, but create a version 1.1 of your plan. "A plan is so you know what you are deviating from." - Capt. Dan Ellrick USMC.
10 points possible.


C. Oral presentation with Slides counts as 30% of GDWP score.
Only one person presents, exactly 7 slides, 15 minute time limit, with a
couple of extra minutes for questions. Notes pages under slides should have
sufficient content so that someone not present can understand what you are
trying to convey.  Remember to start and end on time; presentation skills
and content both count.
1. Presentation and presenter execute at the CIO level while accurately summarizing and supporting proposed processes. 10 points possible.
3. Presenter quality, (includes question handling), 10 points possible.
4. Presentation quality, 10 points possible.

Assignment Scenario:

Your company, GIAC Enterprises, is a small to medium sized growing business. It employs 1,500 employees, including 750 business and IT workers at corporate HQ, 250 employees at the Indonesian office and the remainder remote workers distributed worldwide. GIAC Enterprises has standardized on HP for desktop and laptop systems and Cisco for networking equipment. The servers are more diverse, almost of them run Linux. The company is the largest supplier of Fortune Cookie sayings in the world and prides itself on a rich history as well as cutting edge original research. The current primary product of GIAC Enterprises is the content of the fortunes themselves, i.e., the data. Data is stored and processed in 2 data centers at highly rated colocation facilities, one in the US and one in Indonesia.

On July 31, 2015, GIAC CIO/CISO, Karen Brown, walked into the office of one of the senior engineers, Chris Brown, and noticed a news story on her screen from LATimes:

Together they read the story, the LATimes article was similar to:


The CIO then remarked, “Tell me about that, a couple weeks ago, I was on UA Express 6395 Nashville -> Chicago (ORD) plane that had taxied to the TARMAC when they stopped operations. We were delayed 30 minutes, but when we got to ORD my next flight was delayed 45 minutes and the crazy thing is, the United employees didn’t seem to have a clue. They kept thinking the plane would be here shortly and Chicago is United’s HQ. I pity the poor souls that had their flights canceled.”

Chris said, “Crazy day, WSJ and the NY Stock exchange also had their share of troubles, here let me show you that story.”:
http://www.ibtimes.com/wall-street-journal-homepage-wsjcom-down-nyse-stops-trading-computer-glitch-1999756

“Holy cow, were they hacked? Is this nation state? Or are these people clueless?”

Chris replied, I am not sure anyone knows, if they do, they aren’t talking, at least not yet.

“Hmmm”, Karen remarked, “we ought to review our incident response procedures so that when we make the call whether is it malicious or just a mistake, we have a good chance of being right. I think I will put a team together and I will sleep better if I have a first cut tomorrow about this time.”

Assignment:
Your CIO, Chris Smith, tasks you to create a technical report with the following items:

1) The three glitch scenarios: United Airlines, NYSE, WSJ should be considered guidance for “use cases”, i.e router glitch, computer glitch, web site glitch that have a significant impact.

a) For each glitch scenario summarize the architecture, essentially a critical controls 1 and 2 report. Keep in mind this is the size of GIAC Enterprises, NOT the New York Stock Exchange, (NYSE).
NOTE: feel free to choose the technology involved. For instance, if you read that the Wall Street Journal web servers ran Apache, but you are more familiar with Microsoft IIS, you are encouraged to create your checklist, (sub-assignment “b)” below), using Microsoft IIS.
15 points possible

b) For each scenario create a checklist to help the incident response leader determine if the cause of the glitch is human error or malicious intent. The checklist should be technical in nature and based on a technology that you understand and defined in sub-assignment “a)” above. Make sure to explain the “why” for each step. For each check give examples of what you would expect to find if it was user error or what you would expect to find if it was malicious intent.
30 points possible

c) Direct research for either “a) or b)” document in any: labs, scripts, screen shots, team created videos, interviews, demonstrations, that show you went beyond harvesting web pages on the Internet. This should be documented in the references section of your technical report.
5 points possible.


2) For each glitch, analyze and summarize what each organization did to manage PR:
Look for quotes in news stories and for full points try to find primary source examples, e.g. the Jennifer Dohm United Airlines “router email” or official United Tweets, or press releases from the three organizations etc.
5 points possible

Create a recommendation for each example use case on what they could have done better, (suggestions for improvement).
5 points possible



NOTE: While the executive summary of your paper is at the CIO level, (CIOs
only read the executive summary), the written technical paper should assume
a technical audience.
-- NOTE: when you send the email package, please point out the direct
research that you did. There is a risk that the graders might miss some of
it.
-- NOTE: If you use someone's diagrams or a significant portion of their
material, you must ask for and receive permission to use. Please submit that
with your project.

* * *

Your oral presentation with Slides is scheduled for June 14 at 7:30pm in the
Billie Holiday 1 Room and your graders will be Toby Gouker.

Good luck and enjoy! (Remember that if you have any questions about the
assignment, please contact Toby Gouker and/or Stephen Northcutt).


* * *

Saturday, January 9, 2016

SCORE has published a new Linux Security Checklist

The checklist can be found here. I did a short interview with Simeon Blatchley.

What prompted you to update the checklist, it looks like a lot of effort went into that project?

Simeon: A big problem with security is that documentation is not up to date, and documents/checklists on Linux can kind of be ignored. So we figured that if we put the time to create the document, we should maintain it. Security changes every second, so keeping documentation and instructions accurate and up to date is essential.

They used to say the single most important thing you could do to protect and operating system was keep the patches up to date. Does that apply to linux?

Simeon: I like to compare Linux and Windows systems to a regular and unlocked smartphone. On your typical locked phone [Windows], the primary thing you really can do for security is make sure it is updated/patched regularly, since security is not locally managed. But on an unlocked phone [Linux], you have control over many more aspects of the system (as does an intruder), so you must take greater measures to secure it. Therefore, while it is important to ensure you're patched and up to date, Linux systems in an enterprise environment need to take further measures to prevent exploitation. Most attacks against Linux are well crafted exploiting things normal patching won't protect.

Have you been contacted yet by users of the checklist with questions or suggestions?

Simeon: As far as I am aware, we have not been contacted by any users. However, I have been made aware that it is the main Linux checklist used by Cyberpatriot teams.
What is your favorite variant of linux and why?
Simeon: I personally use Kali, mostly...well for obvious reasons. Plus I studied the martial art so that's cool. Aside from that it looks really good! 

About Simeon: 

Simeon Blatchley is an Analyst at SAIC in Denver Colorado and a Senior at the University of Maryland University College, where he will be receiving his BSc in Cybersecurity. Simeon’s formal immersion in cybersecurity was at 16, when he participated in the AFA Cyberpatriot competition with a Civil Air Patrol team coached by Simeon’s father William Blatchley. The following year Simeon acted as an assistant Coach to the same team (Team Wolfpack), and they won the Cyberpatriot Finals in Maryland at the USAF Cyberfutures conference. Simeon and some cyber minded friends are currently working on starting their own company which will connect highly qualified college students receiving their degree in a computer related field, with jobs and with other people in their field to help facilitate the future of cyber engineering. The company, LinkX RDP, was recently endorsed by NASA and will hopefully launch officially this year. Simeon enjoys playing piano, reading, doing computer stuff, and telling jokes that really aren’t funny.

Phishing and browser security Jan 9, 2016

Interesting morning. It is a very Voggy day on Kauai so I am off to a slow start, was working on the SANS Boston 2016 program, and got a notification I received an email from a grad student team getting ready to work on the Ransom32 problem. They pointed out, "After conducting our initial research into the Ransom32 malware, we have some questions regarding the scope of the assignment. While the published articles we have read suggest that the JavaScript source code that forms the basis of Ransom32 could easily be weaponized to run on Linux or OSX and the Javscript source code might be able to be adapted to run within a browser, the only samples thus far encountered in the wild are Windows PE files created using NW.js and mostly delivered via spearphishing emails. http://blog.emsisoft.com/2016/01/01/meet-ransom32-the-first-javascript-ransomware/. "

Yup. The more things change, the more they stay the same. Nifty Javascript attack, but same delivery; phishing. This actually came up on the GIAC Advisory Board mailing list [heavily sanitized]. A credit union's members were targeted.. response was as follows:
"Quick sounding board for steps taken,

Notification
-Created an alert on the companies web site regarding the phishing attempt.
-Made a post on social media (Facebook, twitter) that the Credit Union
would never ask for Username/Password etc and should also contact us
directly if you have an concerns.

Actions
- The site "harvesting" the credentials appears to have been hacked,
emailed the owners of the site (using the email in the "contact us"
section) to let them know.
- Used the abuse email address in the domain registry to also report that
the site has been hacked.
(Does gmail have a place I can submit for email abuse? its about 48 hours+
after the attack so most likely a moot point but could help someone else if
they want to use the same account)"

All wise and proportional steps. Then, a real treat, Lance Spitzner steps in: 

"First don't feel bad, you are facing a common problem shared by
most organizations.  However to answer your question we have to first ask
you a question.  Are you training your employees to report phishing
attacks, and if so how are you training them and how often?  If you are not
teaching them the indicators of a phishing attack AND how you want them to
report it, then you can't expect them to be effective sensors." 

This is an extremely important point. Until one of these phishing emails gets reported, the security folks can't get involved to take the actions the credit union took. Lance continues:

We see organizations that regularly phish their employees can get the number that
fall victim to less than 10% (sometimes less than 5%) and quite often those
that are falling victim are the new hires.  Same thing with reporting.  The
more you train people on reporting AND the easier you make reporting, the
greater your reporting %.  Warning though, you have to be prepared for
success.  We have seen organizations turn on their "Human Sensors" only to
have their SOC overwhelmed with reports.  That is why we see some
organizations tell their employees if they see an obvious phish, just
delete it. Its the trickier attacks they want reported.  It all depends on
what you want reported and the resources you can dedicate to it.

Thanks!

Lance Spitzner
Director, SANS Securing The Human
Mobile: +1.708.557.6006
Twitter: @lspitzner

I am going to have to ponder this for a while. I can see how to train employees to either report everything they think is suspicious. I can see telling them if you think it is a phish, delete it and move on. But it is not immediately obvious to me how to tell them how to report the trickier attacks. I can do it, (and do), you can do it, but we are security people, we think about this stuff all the time. There are some security company phishing quizzes, opendns, and mcaffe for example. Perhaps they could be incorporated into an organization's security awareness program. Now in the specific case of the credit union:

Some good news, looks like Firefox was blocking the site when the attack
took place, and Chrome started blocking it within 24 hours (and i think

that's awesome, thanks to anyone who works on those applications).

It probably makes sense for organizations to be sure their browsers are taking advantage of the protections available.

The capability is built into most browsers, for example on an El Capitan Mac:
In Safari, Preferences, Security, Warn when visiting fraudulent sites.
In Firefox, Preferences, Security, Block reported attack sites
In Chrome, Preferences, Advanced Settings, Privacy, Protect you and your device from dangerous sites

Phishing will always be with us. We have technology solutions, we have security awareness solutions, we need both and we need to adjust and remind from time to time to lower, not eliminate, the risk.

Saturday, November 7, 2015

Like PCAPs, PCREs?

Yeah, I like PCAPs and PCREs! Gotta a really cool one waiting for the SANS Boston 2016 webpage to be posted. You will have to read to the bottom to get to the joke. Yes, this is real. Name of the company has been changed to protect.

• Responsibility for information cyber security analysis & response with the mission of protecting ACME from internet attacks / threat actors.
• Technical lead for IPS solutions
• Lead initiatives and the implementation of capabilities in order to advance the Cyber Threat program
• Automate threat intelligence gathering and attacker profiles to direct hypothesis-driven searches for indicators of compromise
• Enhance and distribute security incident response and escalation procedures to ensure timely and effective handling of security events and alerts.
• Enhance ACME’s Cyber Security program and strategy to expand threat management services across all business units.
• Maintain industry affiliations that provide ACME with the necessary intelligence to proactively respond to threats. Such affiliations may include NH-ISAC (National Heath Information Sharing and Advisory Center), HiTrust, DHS (Department of Homeland Security), FBI, etc.
• Apply knowledge of technical, analytical skills to ensure the confidentiality, integrity, and availability of all information systems assets and ensure compliance with company policies, procedures, contractual, and regulatory requirements.

Skills and Experience
• Experience building cyber security toolsets and solutions across non-integrated business units.
• Experience with architecture, design, and management of NIPS technologies and best practices 
• Experience with SEIM technologies and best practices, and experience implementing a more robust advanced security data analytics capability.
• Malware detection, analysis, exploitation, containment, and eradication techniques experience (Not just commercial tools)
• A solid understanding of Threat Vector Analysis, Intrusion Detection and Prevention, Incident Management and Response, Risk Assessment and Mitigation methodologies, and Counter Threat Operations.
• Experience monitoring and managing network and host-based intrusion prevention systems actively in-line, Full Packet Capture (with analytics), Sandboxing, data loss prevention, malware prevention systems, vulnerability scanning solutions, DDOS protection, Security Event/Information Management, host-based integrity checking, end-point security and AV. 
• Proficiency in OS platforms, including Linux, Unix, Windows and AIX. Capable of building and maintaining an organization with expert knowledge of information technology functions, practices and business units. Has strong expertise in multiple systems and in the functions and business units supported.
• Knowledge of scripting languages, including python, perl, php, Ruby, and JS. 
• Knowledge of toolsets and frameworks like elasticsearch, splunk, OpenSOC, OpenIOC, STIX, TAXII, CybOX
• Knowledge of information security concepts and theory, and the application of such through technical and non-technical methods.
• Solid understanding of cyber security threats, risks, vulnerabilities and attacks, to include threat actor motives, capabilities, and techniques, with the ability to analyze intelligence data and provide indicators and warnings to healthcare and financial services business functions.
• Demonstrating an ability to work under stress/pressure to meet deliverables, timetables and deadlines.
• Demonstrating personal integrity and high ethical behavior at all times to inspire confidence in clients, peers, partners and employees.
• 5+ years' industry experience in a mission-critical environment.
• Knowledgeable of current and emerging security and information technology standards and practices. 
• Understanding of key InfoSec regulation & frameworks (PCI, GLBA, HIPAA, ISO 27001, HITrust, EHNAC) is a plus.
• Bachelor’s degree required – preferably Computer Science or MIS.

• Must possess an active industry InfoSec related certification (i.e.- CISSP, CEH, CISM).

I am reminded of a scene in the movie Independence Day when Will Smith asks can you really do all that stuff you just said. The CISSP, CEH and CISM are all fine certs, however they aren't going to even start to prepare someone for this list of requirements. The GSE comes close, but this is tailor made for an STI graduate

Monday, September 14, 2015

Ebony Cousins - Cybersecurity expert - TS/SCI CI Poly

Ebony Cousins
Cyber Security Professional

Hephzibah, GA
Transitioning Chief Warrant Officer with 20+ years of Cyber Security Operations, Information Assurance and IT solutions technical leadership and management experience. Extensive proficiency in leading military IT initiatives; strong working knowledge of complex IT networks and related security concerns.

SECURITY CLEARANCE
Top Secret Clearance/SCI with CI Polygraph

WORK EXPERIENCE
Cyber Network Warfare Planner
United States Army - Augusta, GA
August 2013 to February 2014, August 2015 to Present
US Army Cyber Protection Brigade, Augusta, GA, USA. Supervisor Melissa Williams, 706-791-2222. Hours per week: 60
Cyber Network Warfare Planner (8/2013 to 2/2014, 8/2015 to Present)
Key Skills: Cyber Security, Information Assurance, Management, Training & Development, Evaluation & Improvement
Responsibilities: Serves as the Cyber Protection Team (CPT), Cyber Network Warfare Planner for the US Army Cyber Protection Brigade (CPB). Apply comprehensive technical knowledge to Army and Joint planning processes in order to effectively deploy and conduct full spectrum cyber operations. Identify, track and eradicate cyber threats and vulnerabilities directed against DoDIN and Army systems and networks. Coordinate cyber inspections, threat emulation, information systems training and protection for DoDIN and Army organizations as directed. Ensures synchronization and de-confliction of assigned missions between USSCYBERCOM, ARCYBER, and the USA CPB. Mentor, train and evaluate the work performance of subordinates. Interface with Subject Matter Experts (SMEs), both military and civilian; providing consulting expertise on Defense Cyber Operations (DCO).
 
Selected Accomplishments:
·       Recognized by the 780th Military Intelligence Brigade Commander for superior incident response support to the National Cyber Protection Team during Joint Cyber Flag Exercise.

Senior Watch Officer
National Security Agency - Augusta, GA
February 2014 to August 2015
Tailored Access Operations (TAO), National Security Agency – Georgia (NSA-G), Augusta, GA, USA. Supervisor Cleo Lamkin, 762-206-3375. Hours per week: 60
Senior Watch Officer (2/2014 to 8/2015) 
Key Skills: Compliance Management, Risk Management, Training & Development, Presentations, Communication, Technology, Multimedia Instruction, Microsoft Office Suite 2010 Proficient
Responsibilities: Direct representative of National Security Agency-Georgia (NSA-G), Tailored Access Operations (TAO). Supervised 24/7 Computer Network Operations (CNO) activities conducted by joint services military and civilian personnel. Identified, developed, and enforced policies related to conducting and supervising CNO activities; provided technical guidance, ensured legal compliance, conducted risk management analysis, and managed tasking and welfare of vital TAO operational support systems. Coordinated with analyst, software developers, infrastructure engineers, and operators to ensure optimal tactical and strategic-level customer response. Maintained awareness of ongoing events and dynamic requirements, adjusted priorities to assist team members as needed, and prioritized troubleshooting procedures to ensure efficient operations.

Enterprise Cyber Security Operations Officer
United States Army - Kuwait
August 2012 to July 2013
160th Signal Brigade, Southwest Asia Cyber Center, Camp Arifjan, Kuwait. Supervisor: MAJ Christopher Lowrance, […] Hours per week: 60.
Enterprise Cyber Security Operations Officer (8/2012 to 7/2013)

Key Skills: Cyber Security, Information Assurance, Management, Training & Development, Program Evaluation & Improvement, Planning, Communication, Technical

Responsibilities: Planned and conducted 24/7 network security operations and defense across seven countries to include Iraq and Afghanistan, ensuring US and coalition freedom of action within cyberspace. Facilitated and supervised the HP ArcSight installation, upgrade, and training for nineteen remote sites throughout Kuwait and Afghanistan. Enforced Host Based Security System (HBSS) Device Control Module (DCM), Host Intrusion Prevention System (HIPS) and antivirus policies on servers and over 200,000 workstations in Kuwait and Afghanistan. Provided technical expertise and assistance in data collection, correlation and analysis for incident handling through HBSS and HP ArcSight Security Information & Event Management (SIEM). Created global security policies, standards and procedures to help detect, categorize and respond to cyber security threats. Coordinated with external organizations to identify
risky operational practices, develop and implement more effective network defense security solutions and strategies; enhancing the cyber security posture throughout theater.

Selected Accomplishments:
·       Identified requirements for and designed the DoD NIPRNET DMZ Extension plan for the Camp Arifjan, Kuwait Main Control Facility (MCF) per Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIGs).
·        Implemented a Deny All Permit by Exception (DAPE) policy on eight-teen high-side and low-side network firewalls across Kuwait and Iraq.
·       Co-creator of the first Defensive Cyber Operations (DCO) working for the Southwest Asia Cyber Center (SWACC).
·       Provided technical input and supervised team that developed and deployed Rouge System Detector (RSD) coverage plan using a spanning port solution that was commended by DISA inspectors as a module the entire Department of Defense (DoD) could emulate.

Information Assurance Manager
Technology Management
July 2009 to July 2012
513th Military Intelligence Brigade, Augusta, GA. Supervisor: Simon McKenzie, […] Hours per week: 60
Key Skills: Information Assurance, Certification and Accreditation, Vulnerability Management, Business Continuity, Disaster Recovery, Incident Response, Staff Management, Technology Management, Documentation, Communication, Process Redesign, Training & Development
Responsibilities: Served as the Information Assurance Manager (IAM) for a deployable theater-level Military Intelligence Brigade that conducted multi-disciplined intelligence tasking, exploitation, collection and processing of data for Army Central Command (ARCENT). Ensured system interoperability and performed system administration of tactical and garrison systems. Conducted annual business continuity and disaster recovery exercises to evaluate the unit’s ability to respond to a disaster. Ensured Information Assurance Vulnerability Management (IAVM) compliance for over 2,200 workstations and servers on a weekly basis. Designed and implemented initial DoD 8570 IA compliance training and certification program. Managed development of personnel through job related training programs to ensure preparedness to install operate and maintain organic communication systems and Commercial of the Shelf (COTS) equipment.
Selected Accomplishments:
·       Led technical and administrative efforts accrediting three networks under Defense Information Assurance Certification and Accreditation Program (DIACAP), resulting in one receiving a full three year accreditation and the other two receiving Interim Approval to Operate (IATO).
·       Lead technician to test a TS/SCI tunneling package with the Fort Gordon Signal Center to be routed through the Joint Network Node (JNN) to support units without an organic Trojan Spirit.
·       Developed and implemented the Brigade’s first Incident Response Plan for handling investigation and remediation procedures.
·       Designed and implemented initial DoD 8570 IA compliance training and certification program.
·       Ensured Information Assurance Vulnerability Management (IAVM) compliance for over 2,200 workstations and servers.

Network Technician / Computer Network Defense Team Supervisor
Network Management
March 2006 to June 2009
US Army Europe, 44th Expeditionary Signal Battalion, Mannheim, Baden-Wurttemberg, Germany/ Baghdad Iraq. Supervisor: Paul Howard, […] Hours per week: 60
Key Skills: Leadership, Team Building, Communication, Performance Evaluation, Coaching, Mentoring, Technology Proficiency, Logistics, Problem Solving, Documentation & Reporting

Responsibilities:
Planned, established and maintained multiple network links utilizing satellite, radio, and line of site forms of transmission. Played key role in overall health of network, server deployments and security by ensuring network connectivity throughout LAN/WAN infrastructure, providing Tier 2 and Tire 3 support. Trained personnel in communication Data Packages and Joint Network Node operations before and during combat operations in Iraq. Facilitated DIACAP network accreditation transition for both tactical and strategic networks, creating better controls for addressing, accessing, and correcting system vulnerabilities. Created, modified, and maintained network topology diagrams. Published Information Assurance / Computer Network Defense Policy for the 44th Expeditionary Signal Battalion Joint Network Node operators. Maintained command control of all assets by installing SolarWinds monitoring tools.

Selected Accomplishments:
·       Simultaneously managed and maintained six separate Local Area Networks (LAN) separated by over 250 miles in Iraq, supporting users with commercial, non-secure and secure tactical voice and data services.
·       Managed the technical redesign and virtualization of two Technical Control Facilitates (TCF’s) providing services for over 3,000 customers.

Instructor/ Writer/ Operations Officer
United States Army – Augusta, GA
September 2001 to March 2006
447th Signal Battalion, Augusta, GA. Supervisor: SFC Clyde Hudgins, […] Hours per week: 60.
Instructor/ Writer/ Operations Officer (9/2001 to 3/2006)

Key Skills: Training Management, Training & Development, Curriculum Development, Facilitation, Program Evaluation & Improvement, Planning, Presentations, Communication, Technology, Multimedia Instruction, Student Relations, Performance Optimization, Logistics

Responsibilities: Successfully educated and graduated 4000+ highly qualified, hard-working personnel; prepared all graduates for rigorous IT roles annually. Planned and oversaw technical training to improve the capabilities and knowledge base of personnel and students. Provided one-on-one training to students exhibiting difficulty learning and researched and developed training specialized to address specific student shortcomings.  Evaluated training needs and oversaw development and assessment of Program of Instruction (POI) for MOS 25Q (Multi-Channel Transmission Operator/Maintainer). Wrote, revised and continuously fine-tuned courses, lesson plans, lectures, seminars, conferences and teaching materials to capture attention and provide exceptional-quality education while complying with POI and current policies. Developed and implemented intensive hands-on evaluation procedures for radio operations. Served as Battalion Training Officer responsible for comprising and publishing training schedules, coordinating quarterly training briefs, and scheduling personnel for Professional Military Education (PME) training and courses for advancement. In addition served as the Battalion Equal Opportunity (EO) representative; responsible for generating quarterly reports, providing quarterly training and planning ethnic observance programs. Managed facilities, training devices, instructors, and supply requirements needed to ensure student success.

EDUCATION
Bachelor of Science Information Systems Management
University of Maryland University College - Adelphia, MD, 2015

Associate of Science in General Studies
Georgia Military College – Milledgeville, GA, 2008

ADDITIONAL INFORMATION
JOB-RELATED TRAINING
GIAC Certified Enterprise Defender (GCED), 2015 
Joint Network Attack Course, 2013 
Information Protection Technician Course, 2012 
Computer Network Operations Planners Course, 2012 
• Host-Based Security System (HBSS) Administrator
Course, 2012
JNN Network Operations Course, 2007 
• Network Management Technician Course, 2005
• Warrant Officer Candidate School, 2005 
• Joint Network Transport Capabilities – Spiral (JNTC-S) Manager Course, 2005
• Information Assurance Security Officer Course, 2002  


CERTIFICATIONS/LICENSURE:
• Certified Military Instructor
• ITILv3 Foundation Certification in IT Service Management
• CompTIA Security+ Certification,
Global Information Assurance Certification Certified Forensic Analyst (GCFA)
Global Information Assurance Certification Penetration Tester (GPEN)
Global Information Assurance Certification Certified Incident Handler (GCIH)
Global Information Assurance Certification Certified Intrusion Analyst (GCIA)
Global Information Assurance Certification Systems and Network Auditor (GSNA)
Global Information Assurance Certification Security Essentials (GSEC)
Certified Information Systems Security Professional (CISSP)  
Certified Ethical Hacker (CEH)


HONORS & AWARDS:
• Bronze Star Medal
• Meritorious Service Medal (3)
• Army Commendation Medal (6)
• Joint Service Achievement Medal
• Army Achievement Medal (7) 

Friday, September 4, 2015

A personal flamethrower - What could possibly go wrong?

I have no clue how I managed to get down this particular rabbit path, but here I am on a conference call, (sorry David), am a bit bored, (still managed to reply every time my name was called), and ended up with this web page on screen.

For a bit under $1k, you, I, your neighbor, a stranger,  can own a personal, hand held flame thrower with a range of 25'. For a bit more, you can get a 50' range with interchangeable wands for various applications.

All in all a bit strange. If I can offer one tip, this is probably not a good choice for home defense unless your home is very, very flame resistant.

Tuesday, September 1, 2015

Hands on skills, Nicolas Mumaw, GPEN, looking for an opportunity

Nicholas M. Mumaw, GPEN
Digital Forensic Science
Nmumaw001@defiance.edu
www.linkedin.com/in/nmumaw/
Cell (330)703-9419


Education

Bachelor of Science, Defiance College, May 2014
¬Major: Digital Forensic Science       Minor: Criminal Justice
¬
¬Post-Secondary, The University of Akron, May 2010
¬CCNA Networking
Networking Basics
Router and routing Basics

Related Coursework

¬¬Comp TIA Exam Prep ¬Digital Forensics ¬Network Fundamentals
¬¬A+ Practical Applications ¬Computer Security ¬Routing Protocols and Concepts
¬¬Operating Systems ¬Seizure and Forensics Examination ¬Switch Basics and Wireless
¬¬Computer Forensics/Security Ethics ¬Advance Data Recovery ¬WAN Technologies
¬¬Network Forensics ¬Intrusion Detection ¬Mobile Forensics
¬ ¬ ¬
Technical Skills

Advanced program knowledge includes: Windows XP, Windows Vista, Windows 7, Windows 8, Linux, Android, IOS, Word, PowerPoint, Mediashout, FrontPage, Dreamweaver, FTK, FTK Imager, PRTK, Registry Viewer, Winhex, SIFT, Sleuthkit, Helix, Backtrack, VMware, THC-Hydra, Wireshark, TCPDump, Cain and Abel, John the Ripper, Psexec, Metasploit, Nmap, Ophcrack, Nessus, Enum, Netcat, and CoWPAtty.

Basic program knowledge includes: Windows Server 2003, Windows Server 2008, Windws Server 2012, HTML, Python, Excel, Burpe Suite, Zed Attack Proxy, IBM AppScan, Amap, Scapy, Netstumbler, Nikto, and Snort.

Other advanced skills include:
¬Configure routers, switches, access points
Design and build a network according to specifications
Build, upgrade, repair and troubleshoot PCs
¬
¬Work Experience

Sonit Systems LLC  Archbold, OH September 2014 - Present
Helpdesk Technician
Assist in the day to day Network Administration of customers network needs and problems over the phone
Go to customer locations in order to do consulting, setup networks, computer/server repair, and printer service
Work closely with the President and Owner of the organization to help establish a Network Security position
Come up with ideas, implementations, and services which could be provided to customers such as vulnerability assessments, network mapping, compliance checks, and network security sensors

Metalink Technologies  Defiance, OH May 2013 – September 2014
Technical Support
Conducted wireless internet, computer, and home network technical support over the phone and remotely
Joined projects and work with teams to create forms and test programs to verify solution accuracy
¬
Sherwin Williams  Defiance, OH November 2012 - August 2013
Store Associate
¬Worked closely with management to rearrange and organize the entire store according to corporate specifications and plans to increase sales by drawing customer’s eyes
Became a key holder just three months after starting allowing me to open and close the store
Used store systems to perform cycle counts, fulfill orders, and stock inventory
Using verbal skills, helped customers in their projects and any difficulties that they were facing
¬
Travel Centers of America  Lodi, OH September 2009 - August 2012
Lead Cashier
¬As a manager, completed daily paperwork and records as well as creating weekly orders for merchandise
Managed cashiers and porters, delegating tasks as needed within the store
Trained new cashiers, trainees, and porters along with managing productivity by assigning tasks to clean, organize, and restock the store according to planograms to ensure maximum sales
Provided customer service and remediate any customer issues
¬
Defiance College  Defiance, OH September 2011 - May 2012
Computer Technician
Troubleshot and repaired computers across the campus
¬
Internships

Medical Mutual of Ohio  Strongsville, OH July 2013 - August 2013
Security Temp Agent
¬Completed a 160 hour Internship
Ran security scans on web applications to identify vulnerabilities and perform tests to confirm the vulnerabilities
Reported scan results to owners of web applications, coordinated resolution priorities with them, and completed final scans to approve the security correction
¬
Habitat for Humanity  Defiance, OH September 2012 - May 2013
Financial Auditor
¬Created checks and balances for Financials while organizing the statements and tax forms

Bryan Municipal Court Probation Office  Bryan, OH April 2012
Court Probate Assistant
¬Conducted a 10-hour Service Learning project observing court proceedings and probation hearings.

Related Work

Detectives of Defiance: Got Clue?  Defiance, OH January 2012 – May 2014
Executive Board
¬Work with a group of college students and professors to create a real life crime scene to educate high school students attending the “Got Clue?” summer camp where they would learn about the three forms of Criminal Justice Majors: Digital Forensics Science, Forensic Science, and Criminal Justice
Teach a class of high school students about Criminal Justice and Digital Forensics and aid with their investigations of the mock crime scene

DC PC Solutions  Defiance, OH January 2011 – May 2014
President and Project Manager
Aided in the creation of the organization while working with the original project managers
Conduct cost-free technology consulting and repair on networks, computers, printers, and tablets for low-income clients
Conduct executive board meetings as well as organization meetings to discuss projects and project development to collectively identify new opportunities and engage members
HTCIA International Conference  Hersey, PA September 2012
Project Presenter
Selected to present the “Got Clue?” summer camp concept the Detectives of Defiance group to educate adult members of the HTCIA on creative ideas to engage high school and college students

Barberton City Schools  Barberton, OH July 2009
Networking Technician
Design and build the VOIP phone system contained within the new football stadium

Certifications And Awards

GIAC Penetration Tester, June 2014
Analyst ID#8797
Certified American Heart Association First Aid, October 2013
Service Leader Award, April 2011

Volunteer Work

Service Leadership - Student Member, December 2010 - August 2011
Church Service Leader - Audio/Visual Administrator, June 2007 - August 2010
Youth Group Leader - Audio/Visual Administrator, June 2002 - June 2010
Youth Football - Assistant Coach, August 2003 - October 2009
¬
Professional Organizations

SANS/GIAC Advisory Board
Member, June 2014 - Present
High Tech Criminal Investigation Association (HTCIA)
Member, September 2010 – January 2013
Treasurer, January 2013 – January 2014
Member, January 2014 - Present
Infraguard Toledo Alliance
Member, December 2013 - Present
Midwest Criminal Justice Society
Student Member, September 2010 – May 2014