Living through the fun together
I gave this talk at Queensland University on the 31st of August, 2026. Rather than picking apart a single host, it zooms out to the thing that’s not discussed as often: leading a whole intrusion response. The slides are at the bottom of this post.
The session walks through the compromise of a fictional custody business, The Secrets Group, from the first detection to the point where the business has to start telling people. The technical narrative is deliberately messy, the way real ones are. A detection fires on a service account beaconing out of a file server. From there the job is to work outward in both directions: back towards patient zero (a phished workstation, some recon, an Invoke-Kerberoast), and forward through lateral movement into a malicious GPO, a CitrixBleed exploit, credential theft, and tampering with a customer’s contract data. There’s a sleeper on a print server that only wakes up a month later, which is the sort of thing that gets you re-compromised right after you think you’re done.
The parts I care most about aren’t the individual findings. They’re the questions that good tech leads are always thinking about:
- How do you know you’ve found the edge of the intrusion, rather than just the edge of what you’ve looked at so far?
- How do you match tasks to the responders you have, and expand the team mid-incident without drowning the new people?
- How do you build one shared understanding of the incident, then go hunting for the gaps in that narrative on purpose?
- What does the business actually need from you, and when? Leadership, the board, legal, regulators, customer notification, PR, law enforcement all want different things on different clocks.
I also spend some time on where AI genuinely helps in this work today and where it falls over. It’s a good junior analyst for explaining one artefact or drafting the write-up. It’s bad at holding forty hosts in its head, catching the genuinely novel, and being someone who can sign their name to “this is what happened.” Leadership want people to hold accountable, and that doesn’t change.
If you’re on the business side, the aim is to leave with a realistic picture of what technical response involves so you can set expectations when an incident kicks off. If you’re technical, the aim is the reverse: a better feel for the business concerns you’ll be answering to while you work.
There’s a bonus section on Kerberoasting for if I go full kiwi and burn through my planned content too fast.
Further reading on the model that shaped a lot of this thinking, this is a free eBook that’ll be coming out in September. I’ve been lucky enough to get an advance copy, and it’s excellent: dynamicincidentresponse.com.