
Rob T. Lee
@robtlee • 26,818 subscribers
Chief AI Officer, Chief of Research, @SANSInstitute | Cybersecurity Expert & Threat Hunter | Godfather of DFIR | Technical Advisor to US Govt
Videos

18 years ago today, Dan Kaminsky Dan Kaminsky disclosed the DNS cache poisoning vulnerability at Black Hat USA 2008, triggering one of the largest coordinated patch efforts in internet history. Before public disclosure, Dan organized multiple vendors to fix the flaw in secret. Many more legendary stories than could fit here, like how he exposed Sony’s rootkit across more than 568,000 networks and identified critical certificate vulnerabilities. Dan followed what he cared about and his curiosity. As Michael Tiffany Michael J.J. Tiffany put it, “Only Dan thought, ‘I could fix the human eye in software.’” He built DanKam, an augmented-reality app that helped colorblind people see color. Michael hosted Dan while he built the first version and described watching a colorblind houseguest sit at the kitchen table, “crying tears of joy seeing red for the first time.” His mother, Trudy Maurer, may have said it best when she accepted his Lifetime Achievement Award at the 2025 Difference Makers. “Daniel was the catalyst for many achievements across the vast internet spectrum, and I believe Dan truly represented the intersection of technology and humanity.” Mudge, who presented the award, said: “The Lifetime Achievement Award isn’t about what you achieve in your lifetime. That’s part of it. It’s about how many people you influence and bring in and then take it further.” We lost Dan too early from diabetic ketoacidosis in April 2021 at age 42. Some of you are hearing the name Dan Kaminsky for the first time. The coordinated, community-first spirit Dan modeled is the bar. If you're in Vegas this week, you're walking the streets that the legends of security who came before you walked, when they also had no idea what they were doing, facing problems nobody had solved before. They had to figure it out as they went. Just like you're going to do. Thanks to those who contributed to this tribute video: Jeff Moss Jeff Moss, Paul Vixie, Gadi Evron, Lena Smart, Derek Hinch and the many others who shared here.
Rob T. Lee46,767 views • 29 days ago

(4 DAYS BEFORE SUBMISSIONS CLOSE) I get this question a lot about the Find Evil! hackathon: What does “find evil” actually mean? In this case, the name comes from a real command. I built an autonomous incident response agent I built on the SIFT Workstation. Then I typed “find evil” as a prompt into Claude Code. And it did (watch the demo). I was blown away to watch the autonomous agent run a complete C drive forensic analysis, across 200+ tools via MCP. The agent identified threat actor and context, the attack chain, malware deployment method, persistence mechanisms, code injection analysis, network connections, command-and-control (C2) infrastructure, a complete malicious process tree, and a chronological activity timeline. Two days after I shared initial findings, Anthropic released their report on how threat actors were deploying Claude Code with operational tools and letting it go do evil. (Same thing I was doing.) Find Evil! is the first hackathon dedicated to building autonomous AI agents for incident response. 4,178 defenders are working on final Find Evil! hackathon submits. (This number makes me very happy to see so many diving in. And wishing that the thousands more in our community were experimenting with us.) Your job: teach an AI agent to think like a senior analyst, how to sequence its approach, recognize when something doesn’t add up, and self-correct when it gets it wrong. There are FOUR DAYS left to build with us! (Very few of us are actual AI experts. The rest of us including me are learning.) Register: Apply to judge: We need DFIR, AI, cybersecurity, and open-source reviewers who can separate useful autonomous response tools from polished demos. Apply: I am SO EXCITED to see what comes out of this hackathon and goes back to the community. Sponsored by SANS Institute
Rob T. Lee14,405 views • 2 months ago

Watch this clip. Joshua Wright described this exact attack at RSAC five days ago. Today it happened to one of the most downloaded packages on the planet. Attackers hijacked the #Axiosnpm package this morning. 100 million weekly downloads. 600,000 installs of a credential-stealing backdoor in three hours. Joshua Wright and Rich Greene did an emergency SANS livestream this morning breaking down exactly what happened. The part that caught my attention: the attack deployed separate payloads for Mac, Windows, and Linux simultaneously. Josh isn't ready to call it confirmed, but the pattern points to AI acceleration. Josh's full analysis and steps you should take: Watch Josh's keynote if you missed it. SANS Institute edskoudis Heather Mahalik Barnhart Barnhart Robert M. Lee #AxiosCompromise #AxiosSupplyChain
Rob T. Lee18,232 views • 5 months ago
No more content to load