Today is my last day at @Mandiant/ @FireEye

I never could have imagined how formative these last 5.5 years (38.5 dog/consulting years) would be for me personally and professionally.

The people I get to work with every day make this place incredible.

C:\\> type memories.log

1/8
It’s incredibly cool to learn about new forensic artifacts from the researchers, reversers and responders who discovered the artifacts and their value during real investigations. Oh yeah…and they already integrated a parser for it into your tooling. Sick.

2/8
My coworkers and teammates are incredibly smart while equally humble and approachable. TFW you drop a beginner question in a chat and the person who immediately responds (and takes 30 minutes to help you fully understand the answer) literally wrote the book on the topic.

3/8
Thank you to those office mates who encouraged me to continue building my “weird PowerShell stuff” notes and to eventually share it on a team call…then at an internal conference…then at an external conference ( #DerbyCon 2016) as Invoke-Obfuscation. It’s been a wild ride.

4/8
I’m forever grateful to my team’s leadership for letting me travel the globe speaking at more than a few InfoSec conferences. The great friends I’ve made, the experiences I’ve had, and the code I’ve slung at MANY fine coffee shops – I’m forever changed and truly honored.

5/8
To @ItsReallyNick and @TekDefense – thank you for being the best managers I could ask for. You patiently taught me. You fought for me. You had my back when I pushed an aggressive network sig and you helped me learn from it. And most importantly you trusted me. You are rare.

6/8
To the #FLARE #AdvancedPractices team, you are magicians at finding needles in haystacks…and at importing haystacks instead of waiting for them to be delivered to you. Your level of work is the definition of excellence. I’m proud to have served with you.

7/8
It has been an absolute privilege & honor to Find Evil & Solve Crime with the best in the industry.

I’m excited about what’s next! But first some R&R.

PS C:\\> Remove-PSSession -Session DBO
PS C:\\> Start-Sleep -Seconds (60 * 60 * 24 * 7 * (Get-Random @(1..3)))
PS C:\\> SAJB

8/8
You can follow @danielhbohannon.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: