Taz Wake

@tazwake.bsky.social

DFIR & Threat Hunting Professional | SANS Course Author - FOR577 Linux IR Class | Certified SANS instructor | Incident Responder | I have no access to DMs.

Linux Triage Collection with UAC Full disk imaging does not scale across a compromised estate. This guide covers Linux triage collection with UAC, including profiles, artefact selection, the staging trap and how to search what comes back.

Linux Triage Collection with UAC

Full disk imaging does not scale across a compromised estate. This guide covers Linux triage collection with UAC, including profiles, artefact selection, the staging trap and how to search what comes back.

halkynconsulting.co.uk

DFIR tip: `/proc/PID/exe` is a symbolic link to the process executable. `readlink /proc/PID/exe` may expose a replaced or deleted path, but access depends on ptrace permissions and the process still existing.

Endianness: Why Byte Order Matters in DFIR A four-byte field read in the wrong order gives a plausible answer that is completely false. This guide covers big and little endian, how xxd and hexdump render byte order differently, and why XFS superblocks are big-endian.

Endianness: Why Byte Order Matters in DFIR

A four-byte field read in the wrong order gives a plausible answer that is completely false. This guide covers big and little endian, how xxd and hexdump render byte order differently, and why XFS superblocks are big-endian.

halkynconsulting.co.uk

Investigative Interviewing That Stands Up in a Tribunal The interview is where most workplace investigations are decided - and where most go wrong. Preparation, structure, questioning technique and documentation that survive hostile scrutiny.

Investigative Interviewing That Stands Up in a Tribunal

The interview is where most workplace investigations are decided - and where most go wrong. Preparation, structure, questioning technique and documentation that survive hostile scrutiny.

halkynconsulting.co.uk

Linux investigation tip: a filename identifies a directory entry, not the file object itself. Record both device and inode with `stat -c '%d:%i %n' -- FILE`; inode numbers are unique only within one filesystem.

In my long and extremely online life there are two constants, Zionists and Tankies are the same people, the most anti-cop person you know is an undercover cop.

Just think of how sick, twisted and demented you have to be to post this as president knowing it is all a lie because you don’t want to admit you hired an unqualified pool guy - the act of typing this knowing that every word is false.

Bild

Hi Cloud folk, This is what I had to write today. If you are in the EU and possibly have a spare bit of floor or cupboard or shed I'd be eternally grateful for a few days not in the incoherent stress of a hostel that does not want me to stay I am tired Just a moments safety on the way back pls

BildBildBildBild

An Introduction to Threat Hunting Methodology Threat hunting fails as a vibe and succeeds as a process. An introduction to a practical hunting methodology - scoping the ground, forming hypotheses, hunting endpoints - with Linux-flavoured examples.

An Introduction to Threat Hunting Methodology

Threat hunting fails as a vibe and succeeds as a process. An introduction to a practical hunting methodology - scoping the ground, forming hypotheses, hunting endpoints - with Linux-flavoured examples.

halkynconsulting.co.uk

I love Glasgow pretty much any time I visit, but I think they've put on wonders for the Commonwealth Games. It has been a blast visiting and definitely makes me want to come back here more often. I hope the city's traders got a big boost from this as well.

Hey Cyber People! If you are interested in IR and want to look at how to investigate Linux intrusions *and* potentially compromised LLMs, then have a look at sans.org/for577. As an added bonus, if you sit this class in the US, you can get a $900 discount if you book before August 15, 2026. #linux

FOR577: LINUX Incident Response and Threat Hunting

Learn to identify, analyze, and respond to attacks on Linux platforms, including AI and LLM threats, and use threat hunting to find stealthy attackers who bypass existing controls.

sans.org

Security Risk Assessment: 7 Steps to Better Decisions Security spending without assessment is guesswork. A practical walk through the seven-step security risk assessment process: assets, loss events, probability, impact, options, feasibility and cost-benefit.

Security Risk Assessment: 7 Steps to Better Decisions

Security spending without assessment is guesswork. A practical walk through the seven-step security risk assessment process: assets, loss events, probability, impact, options, feasibility and cost-benefit.

halkynconsulting.co.uk

Linux Incident Response: A Practical Guide Linux incident response has changed since 2020. This guide covers preparation, live triage, memory capture with AVML, triage collection with UAC and the artefacts that matter most on a compromised Linux host.

Linux Incident Response: A Practical Guide

Linux incident response has changed since 2020. This guide covers preparation, live triage, memory capture with AVML, triage collection with UAC and the artefacts that matter most on a compromised Linux host.

halkynconsulting.co.uk

Linux Memory Management: A High-Level Overview A high-level tour of Linux memory management - virtual memory, paging, the buddy and slab allocators, the page cache, swap and the OOM killer - with pointers on why each matters to security teams and forensic analysts.

Linux Memory Management: A High-Level Overview

A high-level tour of Linux memory management - virtual memory, paging, the buddy and slab allocators, the page cache, swap and the OOM killer - with pointers on why each matters to security teams and forensic analysts.

halkynconsulting.co.uk

Virtual Memory Areas (VMAs): The Linux Equivalent of the Windows VAD Linux has no Virtual Address Descriptor - instead the kernel tracks process memory with Virtual Memory Areas (VMAs). How VMAs work, how they compare to the Windows VAD, and how to inspect them with /proc, pmap and Volatility…

Virtual Memory Areas (VMAs): The Linux Equivalent of the Windows VAD

Linux has no Virtual Address Descriptor - instead the kernel tracks process memory with Virtual Memory Areas (VMAs). How VMAs work, how they compare to the Windows VAD, and how to inspect them with /proc, pmap and Volatility during incident response.

halkynconsulting.co.uk

Workplace Investigations: A Practical Framework Most organisations only discover they need an investigation process after something has gone wrong. A practical framework for scoping, planning and running workplace investigations that survive scrutiny.

Workplace Investigations: A Practical Framework

Most organisations only discover they need an investigation process after something has gone wrong. A practical framework for scoping, planning and running workplace investigations that survive scrutiny.

halkynconsulting.co.uk

What Assembly Language Is and Why It Matters Assembly language is the human-readable form of the machine code a CPU actually runs. This primer explains how it works and why security professionals benefit from a reading knowledge of it.

What Assembly Language Is and Why It Matters

Assembly language is the human-readable form of the machine code a CPU actually runs. This primer explains how it works and why security professionals benefit from a reading knowledge of it.

halkynconsulting.co.uk

The cyclospora outbreak has reached 7,400 cases across 9 states. The FDA just recalled 1.6 million eggs due to salmonella contamination. Screwworm cases continue to rise. And we’ve just surpassed 2,300 measles cases — breaking 2025’s record. “Make America Healthy Again.”

NIST SP 800-53 Rev 5: What It Is and Why It Pays Off A succinct guide to NIST SP 800-53 Revision 5, what the control catalogue covers, how it is structured, and the commercial and security advantages of aligning with it.

NIST SP 800-53 Rev 5: What It Is and Why It Pays Off

A succinct guide to NIST SP 800-53 Revision 5, what the control catalogue covers, how it is structured, and the commercial and security advantages of aligning with it.

halkynconsulting.co.uk