Current Handlers

Volunteer incident handlers donate their valuable time to analyze detects and anomalies, and post a daily diary of their analysis and thoughts on the Storm Center website. Below you will find Handler details including personal pages, additional scripts or papers, or whatever the respective handler is interested in offering. All content is owned by the respective handler.

Interested in becoming a handler? A roadmap is available to learn how.

John Bambenek

Bambenek, John

John Bambenek is President of Bambenek Labs, a threat intelligence and digital investigations firm. He has spent 20 years in the industry helping research emerging threats and leading large-scale intelligence sharing communities to engage in targeted disruption of criminal activities online. He has developed a variety of techniques to conduct digital surveillance that is used to monitor domain generation algorithms and malware configurations which are used by thousands of organizations world-wide. In addition, he tracks financial transactions of various neonazi and supremacist individuals and organizations. He has spoken at conferences around the world, has published two books in addition to several book chapters and articles, and he once appears on the Daily Show with Jon Stewart.

Twitter: @bambenek

Recent Diaries:

View all diaries by this handler

Guy Bruneau

Jim Clausing


Upcoming Courses:

SANS Rocky Mountain Summer 2024, Denver
June 17, 2024 - June 22, 2024
LINUX Incident Response and Threat Hunting

SANS Cyber Defence Japan 2024 - Live Online, Online | Japan Standard Time
June 17, 2024 - June 22, 2024
Reverse-Engineering Malware: Malware Analysis Tools and Techniques

SANS DFIR Summit & Training 2024, Salt Lake City
August 24, 2024 - August 29, 2024
LINUX Incident Response and Threat Hunting

Instructor Page

Scott Fendley

Jan Kopriva

Jesse La Grew

La Grew, Jesse

Jesse La Grew has been an IT professional within higher education for over 20 years. He holds a variety of GIAC certifications including the GDSA, GCCC, GCFA, GCFE, GCIA, GPYC, GSOC, GCIH, GSEC, GISF, GCTI, GCPM and GSTRT and is also a CISSP. He recently received his Bachelor's Degree at SANS Technology Institute and is progressing through his Master's program at the same institution. Jesse's background in IT started in a desktop support role. This transitioned into a cyber security focus when becoming involved in building and supporting environments meeting PCI and FISMA compliance standards. He currently works as Chief Information Security Officer at Madison College.

Twitter: @stealthcrane
Mastodon: @stealthcrane@infosec.exchange

Recent Diaries:

View all diaries by this handler

Renato Marinho

Marinho, Renato

Renato Marinho is Chief Research Officer at Morphus Labs. His journey in the area began in 2001, when he created Nettion, one of the first firewalls to use the contemporary UTM (Unified Threat Management) concept. Experienced in cyber security, Marinho was internationally recognized in 2016 by his research that unveiled Mamba, the first full disk encryption ransomware. At Morphus Labs, he oversees research, innovation and development of new products. Master and PhD candidate in Applied Informatics, he is also professor at University of Fortaleza teaching Computer Forensics in the post-graduate course. He is also a speaker having presented at Ignite Cybersecurity Conference, BSides Delaware, BSides Vienna, WSKS Portugal and Brazilian CSIRTs Forum.

Twitter: @renato_marinho
Mastodon: @renatomarinho@infosec.exchange

Recent Diaries:

View all diaries by this handler

Russ McRee

Xavier Mertens

Mertens, Xavier

Xavier Mertens is a freelance security consultant based in Belgium. Xavier's own company (https://xameco.be) offers services like incident handling, forensic, SOC activities, and pentesting. He holds GCIA, GFCE, GCFA, GXPN, GREM, GDAT, GNFA, GCTI, GPYC SANS certifications but also CISSP, and CISA. Xavier is a SANS Certified Instructor (FOR610 - Malware Analysis and Reverse Engineering). His blog about security is https://blog.rootshell.be and he is co-organizer of the BruCON security conference (http://www.brucon.org).

Twitter: @xme
Mastodon: @xme@infosec.exchange

Recent Diaries:

View all diaries by this handler

Upcoming Courses:

SANSFIRE 2024, Washington
July 15, 2024 - July 20, 2024
Reverse-Engineering Malware: Malware Analysis Tools and Techniques

SANS London August 2024, London
August 05, 2024 - August 10, 2024
Reverse-Engineering Malware: Malware Analysis Tools and Techniques

SANS DFIR Europe Summit & Training - Prague 2024, Prague
September 30, 2024 - October 05, 2024
Reverse-Engineering Malware: Malware Analysis Tools and Techniques

Instructor Page

Manuel Humberto Santander Pelaez

Santander Pelaez, Manuel Humberto

Mr. Santander Peláez currently serves as the CTO of Transportadora de Gas Internacional in Bogotá, Colombia. His areas of interest are Intrusion Detection, Computer Forensics, Incident Response, SCADA Security, cyber defense, threat intelligence and threat hunting.

Twitter: @manuelsantander
Mastodon: @manuelsantander@infosec.exchange

Recent Diaries:

View all diaries by this handler

Didier Stevens

Stevens, Didier

Didier Stevens (Microsoft MVP Consumer Security) holds many certifications from SANS, Microsoft, Cisco, ... He is a Senior Analyst (NVISO https://www.nviso.be). Didier started his own company in 2012 to provide IT security training services (http://DidierStevensLabs.com). You can find his open source security tools on his IT security related blog at https://blog.DidierStevens.com.

Twitter: @DidierStevens

Recent Diaries:

View all diaries by this handler

Yee Ching Tok

Tok, Yee Ching

Dr. Tok is currently a Senior Consultant at JT Consultancy & Management Pte. Ltd. and a Research Fellow at ASSET (Automated Systems SEcuriTy) Research Group in Singapore University of Technology and Design (SUTD) under the Information Systems Technology and Design (ISTD) Pillar. He was a recipient of the SG Digital (Postgraduate) Scholarship program from Infocomm Media Development Authority (IMDA), and won the Cybersecurity Awards in 2019 under the Professional category for his contributions to the Singapore information security industry. Yee Ching is a SANS Lethal Forensicator and also serves as a Co-Opted Committee Member in the Association of Information Security Professionals (AiSP). For more information, please visit https://poppopretn.com/aboutme/.

Twitter: @poppopretn
Mastodon: @poppopretn@infosec.exchange

Recent Diaries:

View all diaries by this handler

Johannes Ullrich

Ullrich, Johannes

Dr. Johannes Ullrich is the Dean of Research and a faculty member of the SANS Technology Institute. In November of 2000, Johannes started the DShield.org project, which he later integrated into the Internet Storm Center. His work with the Internet Storm Center has been widely recognized. In 2004, Network World named him one of the 50 most powerful people in the networking industry. Secure Computing Magazine named him in 2005 one of the Top 5 influential IT security thinkers. His research interests include IPv6, Network Traffic Analysis and Secure Software Development. Johannes is regularly invited to speak at conferences and has been interviewed by major publications, radio as well as TV stations. He is a member of the SANS Technology Institute's Faculty and Administration as well as Curriculum and Long Range Planning Committee. As chief research officer for the SANS Institute, Johannes is currently responsible for the GIAC Gold program. Prior to working for SANS, Johannes worked as a lead support engineer for a Web development company and as a research physicist. Johannes holds a PhD in Physics from SUNY Albany and is located in Jacksonville, Florida. More Details: http://www.linkedin.com/in/johannesullrich

Twitter: @johullrich
Mastodon: @jullrich@infosec.exchange

Recent Diaries:

View all diaries by this handler

Upcoming Courses:

SANSFIRE 2024 - Live Online, Online | US Eastern
July 15, 2024 - July 20, 2024
Application Security: Securing Web Apps, APIs, and Microservices

SANS Network Security 2024, Las Vegas
September 04, 2024 - September 09, 2024
Application Security: Securing Web Apps, APIs, and Microservices

SANS CloudSecNext Summit & Training 2024, Denver
October 02, 2024 - October 07, 2024
Application Security: Securing Web Apps, APIs, and Microservices

Instructor Page

Rob VandenBrink

Tom Webb

Bojan Zdrnja


Upcoming Courses:

SANSFIRE 2024, Washington
July 15, 2024 - July 20, 2024
Web App Penetration Testing and Ethical Hacking

SANS Cyber Defence Korea 2024, Online | Korean Standard Time
August 26, 2024 - August 31, 2024
Web App Penetration Testing and Ethical Hacking

SANS Cyber Defence Singapore 2024, Singapore
August 26, 2024 - August 31, 2024
Web App Penetration Testing and Ethical Hacking

Instructor Page