Papers, talks & templates

A small archive of writing, presentations, and reusable templates I've shipped to the security community over the years.

2 papers · 4 talks · 3 templates

Written work

peer reading & community drafts
Paper · 2008

Malware 101: Viruses

Published April 2008 Venue SANS Reading Room Format PDF

New insights into establishing incident-handling procedures for the various classes of malware. The paper gives a detailed perspective into malware types and their propagation mechanisms, arguing that response must be tailored to type — and offers handling procedures security personnel can use to quickly contain a threat and reduce business disruption.

Read full paper
Paper · 2010 (draft)

Securing Home Computers

Published Draft, not formally released Venue amanhardikar.com Format PDF

A community-effort guide for home users and students to secure their personal computers using only freely available software. Walks through the basic technologies, builds a secure home network from scratch, and closes with practical best practices for staying safe online without paid product investment or deep technical proficiency.

Read full paper

Presentations given

conferences & internal training
Talk · BSides London

Introducing Opabinia

Venue Security B-Sides London Format Video / YouTube

A short presentation about SSLAuditor (v4.0). Walks through the various checks the tool performs against SSL services and the structure of the report it generates.

Watch on YouTube
Talk · NCC Group

Cryptography 101

Venue NCC Group Internal Format PDF / SlideShare

A grounding in cryptography as the foundation of modern security solutions. Covers block and stream ciphers, asymmetric cryptography (including elliptic curve), hash functions and MACs, and closes with digital signatures and envelopes.

View presentation
Talk · NCC Group

PKI 201 — Key Management

Venue NCC Group Internal Format PDF / SlideShare

Focused on key management — the different types of keys, their lifecycle and transitions, and the X.509 certificate format that underpins most production PKI deployments.

View presentation
Talk · NCC Group

PKI 202 — Architecture Models & CRLs

Venue NCC Group Internal Format PDF / SlideShare

Continuation of the PKI series, examining the various trust models that exist in practice and the different revocation methods (CRL, OCSP and friends) and when each is appropriate.

View presentation

Reusable templates

for KeepNote — pentest workflows
Web Application template
Web Application
KeepNotev1.02012 Nov
External Infrastructure template
Infrastructure (External)
KeepNotev1.02013 Apr
Wireless template
Wireless
KeepNotev1.02013 Apr