Driven by natural curiosity and an allergy for mediocrity; I listen, learn, and lead with purpose.

Speaking
I regularly speak at company events, conferences, and to customers & market analysts.
Select examples are below.




Conference Talks

Getting the crowd's attention. Record attendance at Black Hat 2024

Netsniff-NG Toolkit talk at DerbyCon
1 / What's Under Your Hood? - Hack3rCon
This was my first conference talk where I shared my knowledge on how to implement a custom network monitoring system.
2 / The Netsniff-NG Toolkit - DerbyCon
Presented at DerbyCon on the Netsniff-NG Toolkit. I was a contributor to the project and a primary advocate for it in the industry. It has since been included in SecurityOnion as the default full packet capture solution.
3 / ISLET - LinuxCon
Talked at LinuxCon on ISLET, a tool I developed for training & teaching.
Trainings & Lectures

OpenNSM Video Course on Youtube

ISLET talk at DerbyCon

OpenNSM Video Course on Youtube
1 / ITT Tech, Newburgh Campus
An Introduction to Intrusion Detection & Packet Analysis
2 / Vincennes University
Speaking to students about leveraging Free and Open Source Software (FOSS) in Unix environments.
3 / Marshall University
An Introduction to Network Traffic Analysis workshop
4 / Information Trust Institute, University of Illinois
Training staff on ISLET, a tool I developed that has been used at universities and in private training.
5 / OpenNSM Training Series
Started development of a free Youtube series on network traffic analysis.
All Presentations
Here is a list of most of my presentations over the years. I will organize them soon. Many of them are from earlier in my career when I was a security practitioner or engaged in open-source.
Conference Talks
ISLET: An Attempt to Improve Linux-based Software Training -- XSEDE 2015 July 28, 2015 [pdf]
ISLET: An Attempt to Improve Linux-based Software Training -- AIDE 2015 April 23, 2015 [pdf, html]
ISLET: An Attempt to Improve Linux-based Software Training -- REN-ISAC March 26, 2015 [pdf, html]
ISLET: An Attempt to Improve Linux-based Software Training -- Hack3rcon Nov 14, 2014 [pdf, youtube]
ISLET: An Attempt to Improve Linux-based Software Training -- Information Trust Institute, UIUC Nov 13, 2014 [pdf]
BroLive!: Training for the Future -- BroCon 14 Aug 18, 2014 [pdf]
Intrusion Detection and Packet Analysis: Using Bro to Gain Network Visibility -- ITT-Tech, Newburgh, IN Oct 31, 2013 [pdf, txt, jpg]
Netsniff-NG Toolkit -- Hack3rcon^4 Oct 20, 2013 [youtube, mp4, ogv, pdf]
Netsniff-NG Toolkit -- Derbycon 2013 Sept 29, 2013 [youtube, pdf]
A Look at the Netsniff-NG Toolkit: A High Performance Suite of Networking Tools -- Midwest Open Source Software Conference, University of Louisville May 18, 2013
[html, pdf, png]
Intro to Network Traffic Analysis -- Hacker Hotshots, Concise Courses Feb 12, 2013 [html, youtube]
A PCAP Workshop -- Hack3rcon^3 Workshop Oct. 19-21, 2012 [html, [pt1:youtube, avi, mp4, ogv | pt2:youtube, avi, mp4, ogv], txt, odp, pdf] [video mirror] \
- (Slides used in course, "Hacking Techniques and Intrusion Detection", Ali Al-Shemery, Assoc. Prof., Princess Sumaya University for Technology (PSUT))
An Introduction to Traffic Analysis: A Pragmatic Approach -- Marshall University, AIDE Conference May 21-25, 2012 [html, youtube, avi, mp4, ogv, odp, pdf] [video mirror]
FOSS for Unix Administrators -- Vincennes University, Jasper Campus 2011
What's Under Your Hood: Implementing A Network Monitoring System -- Hack3rcon 2 Oct. 21-23, 2011 [youtube, avi, mp4, ogv, ppt, pdf] [video mirror]
Open Network Security Monitoring Group Presentations
Rsyslog Logging Infrastructure -- 02-02-2015 [youtube]
ISLET -- 10-20-2014
Tcpdump -- 09-29-2014
Implementing a Network Monitoring System -- 09-22-2014
Bro -- 09-15-2014
Trafgen -- 09-08-2014
UIUC ACM Linux User Group Presentations:
GNUplot, InfluxDB, Grafana -- 04-16-2015 [youtube]
Gitlab, Puppet -- 03-09-2015 [youtube]
Linux Kernel Capabilities -- 02-23-2015 [youtube]
strace -- 02-16-2015 [youtube]
Nmap -- 02-09-2015 [youtube]
PXE Boot, Vagrant -- 02-09-2015 [youtube]
Docker, Quiz, Sudo -- 01-26-2015 [youtube]
Docker -- September 2014
Linux From Scratch series -- March - May 2014
Creating Vagrant Environments -- March 2014
Introduction to Linux Networking -- February 2014
Awk Primer -- February 2014
Dubois County Linux User Group Presentations:
Huntingburg group turning Fourth Street into a WiFi hotspot -- html
Automated Distributed IDS w/ SecurityOnion -- DCLUG May 9, 2013
X11 forwarding w/ SSH -- Ibid.
XQuartz (X11 replacement) on OSX -- Ibid.
MacTex Distribution on OSX -- Ibid.
GeoIP w/ Wireshark -- Ibid.
Rpcapd (Windows) -- Ibid.
Intro. to Github -- Ibid.
Ewhois-query script -- Ibid.
Ninite application updater (Windows) -- Ibid.
Mandiant's Redline (Windows forensics) -- Ibid.
Cisco - Configure SPAN ports -- Ibid.
Wireless Hacking -- DCLUG Feb 3, 2013
Messing with PCAP's Containing Raw Wireless Traffic -- Ibid.
A look at LaTeX -- Ibid.
Writing Security Tools with Bash -- Ibid.
A Brief Look at the Linux Network Stack -- DCLUG November 4, 2012
A Detailed, High-Throughput /etc/network/interfaces configuration on Ubuntu Server -- Ibid.
Getting Things Done with awk/gawk -- DCLUG August 5, 2012
Netsniff-NG - a Performant Sniffer -- Ibid.
ifpps - Network Stats -- Ibid.
vnstat - A Console Based Traffic Monitor -- Ibid.
CPU Affinity and Interrupt Binding on SMP systems -- Ibid.
Primer on Shell programming with sh/bash -- Ibid.
A Look at a Production Sensor/NMS -- Ibid.
Interface/Network Stats on Linux ( ifpps, tcpstat, atsar ) -- DCLUG June 3, 2013
Network Stress Testing on Linux ( hping3, trafgen, iperf ) -- Ibid.
sed primer -- DCLUG April 8, 2012
Bash Editing Modes: vi and emacs -- Ibid.
Bash Globbing (expansion) -- Ibid.
htop - a better top -- Ibid.
A Brief Look at BPF Assembler -- Ibid.
Networking with Linux -- DCLUG December 4, 2011
Introduction to Moving Text Files Between Windows and the Unices: newlines, carriage returns, tr, sed, od, hexdump -- DCLUG November 16, 2013 [txt]
FreeBSD: sockstat -- Ibid.
Network Throughput Testing with iperf -- DCLUG October 2, 2011
An Introduction to PF -- DCLUG September 4, 2011
Remote Logging with syslogd -- Ibid.
Host Intrusion Detection with OSSEC -- Ibid. [odp]
Keeping Time with ntpd -- DCLUG August 7, 2011 [odp]
Remote Logging with syslogd -- Ibid.
(DNS) Transaction Signatures in BIND -- Ibid.
Using netstat - A Look into the Networking Subsystem -- Ibid. [txt]
Intro to GPG -- DCLUG April 3, 2013 [txt]
OpenSSH with Pub-Key Authentication -- Ibid. [odp]
Passwords in Depth: Hashing, Salting, Storage, and Attacks -- DCLUG February 6, 2011 [odp]
/home files -- DCLUG November 7, 2010 [odp]
smbclient/mount.cifs -- Ibid. [zip]
netcat -- Ibid.
Network Tools -- DCLUG October 3, 2010 [zip]