Speaking, teaching, and community

A partial record of the conferences, courses, and communities I've contributed to over the years.

M3AAWG — Messaging, Mobile, Malware Anti-Abuse Working Group

M3AAWG is the venue I've contributed to most consistently. Over multiple sessions I've presented on email-related threat intelligence, telemetry design, and how to combine third-party data with in-house feeds so that machine-learning classifiers and reputation systems make the most of every signal. I've also served on the M3AAWG GDPR working group.

The M3AAWG audience is other practitioners — ISPs, mailbox providers, security vendors, and law enforcement liaisons — which makes it a good forum for technical detail rather than product talks.

NCFTA — National Cyber-Forensics and Training Alliance

The NCFTA is the teaching and industry-outreach arm affiliated with the FBI's cyber research work. I've given multiple presentations at NCFTA-adjacent security conferences on threat-intelligence topics.

Texas ISF — Information Security Forum

Most recently I presented on mobile threat intelligence at the Texas ISF, covering how on-device telemetry can be turned into actionable protection for enterprise mobility programs.

Training courses I've taught

I've taught multi-session courses on using Linux and the UNIX shell to surface anomalies in logs and raw data — practical, hands-on material for analysts who want to reach for grep, awk, jq, and a well-placed sort before they reach for a dashboard.

I've also taken (and put to work) multiple courses on running meetings and facilitating groups through brainstorming into actionable outcomes. That skill compounds; it is genuinely why the technical work ships.

I have almost certainly forgotten to list a conference or two here. If we've shared a stage or a hallway conversation, feel free to remind me.